Overview
The City of Vienna has suffered a cyberattack in which unidentified attackers copied approximately 26,000 internal documents containing information about nearly 6,000 people.
Municipal officials suspect specialized artificial intelligence software was used to identify a security vulnerability, although investigators have not confirmed the exact method of intrusion.
Vienna’s Chief Information Officer, Klemens Himpele, said the city first learned about the incident on September 9 through Austria’s Computer Emergency Response Team (CERT).
Access to a vulnerability in the municipal system had reportedly been advertised for sale on an online forum before authorities received the notification. Working with Austria’s Directorate for State Protection and Intelligence (DSN), the city subsequently identified and closed the security gap.
By then, the attackers had already accessed an internal documentation platform and extracted files containing approximately 9 gigabytes of information.
The compromised material included training records and project documentation, some of which contained personal information belonging to municipal employees, residents and contractors.
Hackers may have used AI to identify security vulnerability
Investigators suspect the attackers employed specialized AI-powered scanning software to locate weaknesses in the city’s digital infrastructure. Such tools search for vulnerabilities that provide access to confidential information, potentially allowing attackers to extract documents without gaining broader administrative privileges.
Authorities have ruled out phishing as the likely entry method at this stage of the investigation. The suspected use of automated vulnerability scanning remains under examination, and officials have not identified the individuals responsible.
Himpele said the attackers never gained direct control of Vienna’s municipal IT infrastructure or user accounts. The intrusion was limited to access through the compromised documentation platform, where the attackers copied files rather than taking control of operational systems.
The distinction is relevant to the scope of the incident. Although the attackers obtained a substantial volume of internal records, city officials reported no evidence of unauthorized control over municipal systems or accounts.
Personal information of nearly 6,000 people compromised
The approximately 26,000 copied documents contained information relating to almost 6,000 individuals. According to municipal officials, the affected group includes around 2,000 city employees, approximately 2,900 residents and more than 800 contractors working with Vienna’s administration.
Most of the exposed information consisted of names and email addresses. Some documents also contained more sensitive personal details, including employees’ sick-leave records and International Bank Account Numbers (IBANs).
The presence of financial and employment-related information increases the sensitivity of the stolen material, even though most affected records contained basic identification or contact details. Officials have not provided a detailed breakdown of how many individuals had their more sensitive information copied.
Vienna’s administration is identifying and contacting the people affected by the incident. The notification process follows the discovery of personal information within the stolen documents and the subsequent examination of the compromised platform.
Vienna reports no extortion or publication of stolen data
According to Himpele, the city has found no indication that the copied documents have been publicly released. Municipal authorities also reported receiving no ransom demand or other attempt at extortion connected to the cyberattack.
The investigation remains focused on how the attackers obtained access, what information they extracted and whether the stolen files have been distributed elsewhere. Officials’ statements about publication reflect the information available to the city at the time of disclosure.
Vienna has closed the identified security vulnerability with assistance from Austrian security authorities. The city is continuing its response by notifying affected individuals and assessing the information contained in the copied documents.
“We can only apologize,” Himpele said, acknowledging the exposure of personal information held within Vienna’s internal documentation systems.








