A cyberattack that began September 1st has encrypted the central IT systems of Stadtwerke Landsberg, a municipal utility in Bavaria that provides electricity, water, wastewater treatment, district heating, fiber connectivity and other local infrastructure.
The utility’s office and communications systems are disrupted, leaving employees with limited access to phone and email, but operational systems responsible for electricity, water and other essential utility services were unaffected and continue to operate normally.
Stadtwerke Landsberg said it can’t yet rule out whether attackers accessed or stole customer data, including names, addresses, phone numbers, email addresses and bank information.
Jeremiah Fowler, Cybersecurity Researcher, Black Hills Information Security:
Stadtwerke Landsberg Cyber Attack: An incident like this serves as a reminder that smaller and regional infrastructure providers face the same threats as national utility providers, but they often don’t have comparable cybersecurity budgets or staffing to face the growing threats. This is also a good example of why it is important to have segmentation between business IT networks and operational technology. The ability to isolate compromised systems can also help prevent a cyberattack from becoming a doomsday scenario.
Attackers may see regional critical infrastructure as low hanging fruit when it comes to being a target and these systems could also serve as testing grounds for larger attacks against bigger targets. Another concern is the potential theft of PII. Targeted phishing attempts are a real concern when individuals can be connected to services. Criminals would know account numbers, payment history, and much more that makes these attempts believable and much more dangerous.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
Stadtwerke Landsberg runs electricity, water, wastewater, heating, fiber, and EV charging for a Bavarian town. When it gets breached, the attacker gets a near-complete household profile, names, bank details, addresses, and phone numbers for services residents can’t switch away from. You can change your grocery store after a breach. You can’t change your municipal water provider.
IT/operational technology (OT) segmentation kept Landsberg’s water and power running. That’s the difference between a data breach and a service outage. The thirty-plus U.S. water systems hit across seven states in July show what happens without it.
This happened the same day Germany blamed Russia for a drone strike at Leipzig/Halle airport and saboteurs hit two power substations. I don’t think the attacks are connected, but the operating environment for municipal utilities has changed. Landsberg follows GSW Kamen in June and Windsbach in July.
Article 34 of the General Data Protection Regulation (GDPR) requires notifying affected individuals only when the risk to them is high. Landsberg issued one six days after the encryption.
Ransomware crews want the data. Nation-state actors want the infrastructure. A municipal utility serving one Bavarian town is expected to defend against both.
Noelle Murata, Chief Operating Officer, Xcape, Inc.
A ransomware event against a municipal utility managing electricity, water, wastewater treatment, district heating, and fiber connectivity highlights the multifaceted risk exposure facing regional infrastructure providers. While Stadtwerke Landsberg successfully isolated its operational technology (OT) environment to keep core public services running, central administrative IT systems were encrypted, leaving staff without routine communication tools and raising immediate data exfiltration concerns. The good news is that essential utility delivery remained online during this incident; the bad news is that when multiservice utilities succumb to compromise, the potential failure modes multiply rapidly across a community. The precise initial entry vector and the extent of customer data theft remain unconfirmed.
This incident arrives as German authorities pivot toward a fundamentally proactive cyber posture. Spurred by domestic political activism from anti-fossil fuel movements and internal extremism, along with heightened external threats following the Russian invasion of Ukraine, Germany recently updated legislative frameworks to permit active cyber defense and offensive countermeasures. This reform transforms national strategy from a traditionally reactive stance to one focused on deepening intelligence around specific threat actors, disrupting attacker infrastructure, and deploying counter-intelligence.
Cybersecurity professionals have long debated the efficacy of active defense. As Germany operationalizes these new spy laws, defenders will closely monitor whether proactive disruption deters threat actors or simply accelerates adversarial tactics against critical infrastructure.
Her Critical Takeaways
- Operational isolation preserved core municipal services at Stadtwerke Landsberg, but administrative IT encryption created severe communication disruptions and data breach risks.
- German legislative reforms mark a major strategic shift from reactive defense to proactive cyber countermeasures and intelligence gathering against internal and external actors.
- Security leaders must continuously validate active directory boundaries and cross-domain access controls to prevent administrative IT compromises from threatening operational networks.
Mark my words, something like this is coming to the USA soon. I say that because The CISA is about to be defunded leaving critical infrastructure undefended. Which is bad for everyone.
N-able warns MSSPs, MSPs & orgs: patch critical N-central vulnerability NOW
Posted in Commentary with tags Hacked on September 8, 2026 by itnerdN-able is urging users of on-premises N-central to immediately apply its patch for an unauthenticated remote code execution (RCE) vuln to its N-central endpoint management platform, as it’s currently being actively exploited. The platform is widely used among managed service providers (MSPs and MSSPs), and many internal corporate enterprises are also users.
The vulnerability is tracked as CVE-2026-86218 with a CVSS score of 10/10, and was discovered after N-able patched two other flaws in N-central.
“This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited. We communicated this 2026.3 hotfix earlier today, and we want to use this post as a reminder to upgrade immediately if you haven’t already, so we can help keep you and your customers protected,” the company’s alert reads. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range.”
The alert also notes that N-central hosted environments don’t require the patch as it was deployed server-side.
You can read the alert here: N-central Security Update – Take Action to Apply 2026.3 HF4 – N-able
Waseem Ahmed, Head of Engineering at Secure.com
N-able makes N-central, software that IT teams and managed service providers use to watch over and control large numbers of customer computers from one central console. That reach is exactly why this bug is so dangerous.
A single flaw rated 10 out of 10 lets an attacker run code on the N-central server without any login or password first, so one weak spot can open the door to every client network hanging off that platform. Attackers love this kind of target because it turns one break-in into many.
On-premises teams should apply the 2026.3 HF4 hotfix right now, hunt their logs for scans from the flagged IP range, and look for strange new admin accounts. Trusted management tools deserve the same hard scrutiny you give the front door, because attackers already treat them as the shortest path in.
Suzu Labs CTO Denis Calderone:
The severity really comes down to the unprecedented amount of trust it has over its operating environment. It has so much control that you can basically think of a compromised N-central server as having control of a fleet of trojanized nodes; since you own the server, you automatically control all of its nodes. N-able is commonly deployed as an MSP tool, and oftentimes the end client isn’t even aware that they have N-able running because the MSP often white labels the tool as their own. What really worries me is the organization that doesn’t know they have N-able combined with the MSP that hasn’t patched yet. If you want an example of “history repeating” venture back to 2021 when Kaseya VSA got similarly popped; same results.
And the velocity here has our attention. This is N-central’s fourth emergency hotfix in five weeks and their fifth CVE since August. Huntress confirmed a compromised customer environment on September 4, two days before this patch even dropped. Someone is actively picking this platform apart, and the downstream businesses that are most exposed have no mechanism to even know whether their MSP has kept up with the patches.
If you use on-premises N-central, you need to patch all the things ASAP as it is a safe bet that the bad guys are going to leverage this against you if your on-premises N-central instance is attacked.
Leave a comment »