Menu
Browse
Date:

Apr 2022

Location:

Austria

Summary

A ransomware attack using the "Black Cat" Trojan targeted Höhere Technische Bundeslehr- und Versuchsanstalt St. Pölten, encrypting educational materials like school books but failing to compromise sensitive student data, grades, or critical systems due to layered security defenses. The institution's IT specialists swiftly detected the intrusion, initiated an investigation, and filed a police report while confirming no disruption to major examinations. Attackers, suspected to be foreign-based, accessed only non-critical content, but the incident required reconfiguration of approximately 1,100 computers across the network.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around April 1, 2022, unidentified hackers deployed the "Black Cat" cryptotrojan against Höhere Technische Bundeslehr- und Versuchsanstalt St. Pölten (HTL St. Pölten) in Austria. The attackers infiltrated the school's network and successfully encrypted pedagogical materials, specifically Schulbücher (schoolbooks) used for educational purposes. The institution's layered cybersecurity defenses prevented broader compromise, protecting sensitive areas including student data, grades, and administrative systems through additional antivirus protections. The attack was rapidly detected by the school's internal IT specialists, who contained the intrusion before critical infrastructure could be affected. While the hackers accessed non-sensitive systems, they were unable to exfiltrate or encrypt protected data repositories.

Cyber Incident Image

HTL St. Pölten's incident response required the reinstallation of software on 1,100 affected computers to eliminate residual threats, though the process did not endanger academic operations such as the Matura (final exams). Director Martin Pfeffel filed a formal criminal complaint with authorities, though the investigation yielded no immediate attribution beyond suspicions of foreign involvement by the hacking group. No ransomware payment demands or communication with attackers were disclosed in available reports. The encryption of pedagogical materials caused temporary disruption to teaching resources, but core educational functions remained operational throughout the incident. Forensic analysis confirmed that the attackers gained no persistent access to secured network segments after initial detection.

Sources
Sources available to members
1 source