Security2 publishers3 min readPublished
Stadtwerke Landsberg names eight service lines that stayed up while its office IT was encrypted
The Bavarian city utility was encrypted in the night into September 1 and told customers six days later that power, water, heating and five other operations kept running, while it still cannot rule out that customer bank details were taken.
The Watch · Security desk

What happened
- Stadtwerke Landsberg KU, a city-owned utility in Bavaria, says criminals encrypted its central IT systems in the night into September 1.
- The utility cannot rule out access to or theft of customer names, addresses, landline and mobile numbers, email addresses and bank account details.
- No ransomware group has been named, and the utility has not said whether an extortion demand was received.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- contradiction The claim that supply was untouched and the admission that forensics is unfinished sit in the same document, and the notice never describes the boundary that held, so the segmentation outcome rests on the operator's account until the investigation closes.
- constraint A peer utility can copy the containment sequence from this notice, but the notice names no group and no indicators, so there is nothing to hunt with.
- exposure The fraud risk transfers to customers while the forensics are open, and the utility's own guidance assumes attempts on their accounts, down to test debits of tiny amounts.
The containment sequence came out of a plan the utility already had. Stadtwerke Landsberg cut every internet connection and shut systems down to reach what it called a safe and stable state [7]. A crisis team has been working nearly round the clock, and external cyber security specialists were brought in to analyse the scope of the attack and support the rebuild [8]. For many processes the utility switched to fallback procedures it had prepared in advance, and it says the rebuild of affected systems is on schedule [9]. The incident was reported to the responsible authorities within the deadline and a criminal complaint was filed [10].
Staff "are currently only available to a limited extent by phone and email", the utility said [6], and the notice gives one number, 08191/9478-0, for urgent inquiries [5]. Six days passed between the night of the attack and the customer notice [22].
Eight operations are listed as unaffected [4]: the electricity grid, the water supply, the sewage plant, district heating, the fibre network, the charging infrastructure, the Inselbad and the parking garages [3]. The notice does not explain how those systems were kept separate from the IT that was encrypted [25]. Forensic examination of how the attack unfolded is still running [11].
The utility says it cannot conclusively assess whether personal data was accessed or exfiltrated, and it cannot rule it out; the categories in scope are name, first name, address, landline and mobile numbers, email address and bank account details [11][12]. Its advice to customers: check statements for very small debits, because criminals often run a test transaction before a larger one, and report anything suspicious to the bank and to the data protection officer [13]. Payment details for the utility have not changed, and it says it will never contact customers directly to request sensitive data such as credit card information [14].
For anyone else running a Stadtwerk, the notice is thin where it counts. No ransomware group has been named and the utility has not said whether it received an extortion demand, according to The Record [15]. Germany's BSI has repeatedly identified ransomware as one of the country's most serious cyber threats [16].
Landsberg was not the only German infrastructure story that day. The federal government formally blamed Russia for a drone attack at Leipzig/Halle airport, and saboteurs struck two power substations [18]. Investigators found improvised devices near the Turnow-Preilack substation in Brandenburg, where one caused a short circuit without significant disruption to public supply. Hours later, several power-plant units briefly went offline after an attack at Amprion's Rommerskirchen substation in the west, without threatening grid stability [19]. Police arrested a 48-year-old man the next day over sabotage at power installations in Brandenburg, North Rhine-Westphalia and Saxony, and two handwritten letters claiming sole responsibility cite the writer's opposition to electricity generation from fossil fuels [21]. The Record reported that there is no indication the Landsberg hack is connected to any other incident [20].
A municipal utility serving Kamen, Bönen and Bergkamen in North Rhine-Westphalia was hit in late June, internal systems were disrupted for weeks, and the operator later said attackers may have accessed older backups containing personal data [17].
What to watch
- Whether forensics turns "cannot be ruled out" into a confirmed exfiltration, or Landsberg customer data appears on a leak site.
- Whether a ransomware group claims the encryption or an extortion demand becomes public.
- Whether the rebuild holds to the schedule the utility says it is meeting, or drags out like the Kamen case.