Cyber Incident Victim: Höhere Technische Bundeslehr- und Versuchsanstalt St. Pölten
Date:
Apr 2022
Location:
Austria
Summary
A ransomware attack using the "Black Cat" Trojan targeted Höhere Technische Bundeslehr- und Versuchsanstalt St. Pölten, encrypting educational materials like school books but failing to compromise sensitive student data, grades, or critical systems due to layered security defenses. The institution's IT specialists swiftly detected the intrusion, initiated an investigation, and filed a police report while confirming no disruption to major examinations. Attackers, suspected to be foreign-based, accessed only non-critical content, but the incident required reconfiguration of approximately 1,100 computers across the network.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On or around April 1, 2022, unidentified hackers deployed the "Black Cat" cryptotrojan against Höhere Technische Bundeslehr- und Versuchsanstalt St. Pölten (HTL St. Pölten) in Austria. The attackers infiltrated the school's network and successfully encrypted pedagogical materials, specifically Schulbücher (schoolbooks) used for educational purposes. The institution's layered cybersecurity defenses prevented broader compromise, protecting sensitive areas including student data, grades, and administrative systems through additional antivirus protections. The attack was rapidly detected by the school's internal IT specialists, who contained the intrusion before critical infrastructure could be affected. While the hackers accessed non-sensitive systems, they were unable to exfiltrate or encrypt protected data repositories.

HTL St. Pölten's incident response required the reinstallation of software on 1,100 affected computers to eliminate residual threats, though the process did not endanger academic operations such as the Matura (final exams). Director Martin Pfeffel filed a formal criminal complaint with authorities, though the investigation yielded no immediate attribution beyond suspicions of foreign involvement by the hacking group. No ransomware payment demands or communication with attackers were disclosed in available reports. The encryption of pedagogical materials caused temporary disruption to teaching resources, but core educational functions remained operational throughout the incident. Forensic analysis confirmed that the attackers gained no persistent access to secured network segments after initial detection.
