A municipal utility in Bavaria, Stadtwerke Landsberg, experienced a cyberattack last week that led to the encryption of its central IT network. Despite the disruption to office systems, essential services such as electricity and water remain unaffected. The incident, which began on September 1, prompted the utility to disconnect compromised systems from the internet and engage a crisis team along with external cybersecurity experts to handle the situation. While the utility described the event as an encryption attack, it has not named any specific ransomware group nor confirmed if there has been any extortion attempt.
Stadtwerke Landsberg has warned customers about the potential exposure of personal data, which may include names, addresses, phone numbers, email addresses, and bank details. The utility’s staff are currently limited in their availability via phone and email as forensic investigations continue. This event highlights a persistent threat landscape for German companies and public-sector organizations, with ransomware being identified as a significant challenge by Germany's federal cybersecurity agency, the BSI.
The attack on Stadtwerke Landsberg coincided with a tense period for Germany’s critical infrastructure. On the same day, the German government accused Russia of a drone attack at Leipzig/Halle airport, and two separate power substations were targeted by saboteurs, albeit without significant public disruption. Police have since arrested a suspect in connection with these acts of sabotage, which appear to stem from opposition to fossil fuel energy.
This incident underscores the increasing complexities within the cybersecurity arena, prompting the German government to introduce new legislation that empowers intelligence agencies to hack foreign systems and disrupt adversaries’ operations in response to evolving threats.

