Austria’s Ministry of the Interior (BMI) has confirmed it was the victim of a sophisticated cyberattack that breached approximately 100 government email accounts. A criminal complaint has been filed and an investigation into the attack vectors is underway.
The “targeted and professional” attack prompted the ministry to disconnect its mail servers from the internet as a precautionary measure. The 100 accounts of the approximately 60,000 BMI email addresses were partially affected. Employees were directly informed, affected systems were isolated and external IT security experts were brought in, which is standard in such cases.
While the breach caused temporary disruptions to some official communication, officials confirmed that no sensitive personal data of Austrian citizens or critical law enforcement information was compromised.
Due to the nature and professionalism of the incident, officials have suggested the attack may have been perpetrated by a state actor, though no specific group has yet been identified.
The BMI released a statement noting: “Operational capacity is fully ensured and essential IT services remain available.” Police information systems, databases, registers, or personal data of citizens were not affected by the cyberattack, the ministry stated. A criminal complaint for unlawful access to a computer system has been filed with the public prosecutor’s office, and investigations have been initiated.

