Ransomware at Sudwestfalen IT disrupts more than 70 German municipalities
- Organization
- Sudwestfalen IT
- Exploit
- Ransomware
- Industry
- IT Services
Sudwestfalen IT, a municipal IT service provider in western Germany, was hit by ransomware early on Monday, October 30, 2023. To stop the encryption spreading, the provider cut the connections between its data centres and its customers, which severely limited local government services across the region it serves.
More than 70 cities, districts and municipalities were affected, most of them in the state of North Rhine-Westphalia, covering a combined population of roughly 1.7 million. Town halls lost email and telephone service, public-facing websites went down, and back office functions including resident registration, registry offices, vehicle registration, cemetery administration and municipal finance systems became unavailable or had to be handled on paper.
The timing compounded the disruption. German security specialists noted that municipalities process a heavy volume of payments at the end of the month, including salaries and social assistance. German police, state cybercrime authorities and the Federal Office for Information Security opened investigations, and prosecutors said they expected a complex and lengthy inquiry.
The Akira ransomware group was subsequently identified as responsible. Investigators found the attackers reached the internal network through a poorly maintained VPN appliance protected by a weak password and not covered by multi-factor authentication. Sudwestfalen IT declined to pay a ransom and needed months to return to normal operations.