2026-08-18NOTABLEDeliberate trace removal turned a scoped breach notification into a blanket one at an Austrian public-law body
Arbeiterkammer Oberösterreich cyberattack (2026)
incident · incident:ak-oberoesterreich-cyberattack-2026-08 single-source-victim
Attack on the Upper Austrian Chamber of Labour's IT systems on 2026-08-10, disclosed to members on 2026-08-16. Unknown perpetrators reached parts of the IT estate and obtained access to data; the organisation states the extent cannot be established (nor whether and which members' personal data were specifically affected) because the attackers deliberately removed the traces, so it is treating all member data it holds as potentially affected and notifying every member individually by post under Article 34 GDPR. Police and the Austrian data protection authority were notified and the whole data and IT infrastructure was moved into a segregated environment. No ransomware family, actor or initial-access vector has been disclosed by any party (Arbeiterkammer Oberösterreich, 2026-08-16; APA via news.at, 2026-08-17).
Aliases: AK Oberösterreich breach
Coverage
1
first 2026-08-18 → last 2026-08-18
Latest activity
2026-08-18
Deliberate trace removal turned a scoped breach notification into a blanket one at an Austrian public-law body
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector · regions: europe
Sources cited
2
2 hosts
Defender insights
What each entry about Arbeiterkammer Oberösterreich cyberattack (2026) tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- StealthIndicator Removal
Stealth TA0005
T1070Indicator Removal×1
Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity. Rather than broadly removing evidence, adversaries may target specific artifacts that appear anomalous or are likely to draw scrutiny, while leaving sufficient data intact to maintain the appearance of normal system behavior.
Evidence: 2026-08-18/arbeiterkammer-ooe-anti-forensic-wiping-blocks-scoping · ATT&CK page ↗
Entries about Arbeiterkammer Oberösterreich cyberattack (2026) (1)
Where this entity is cited
Source distribution
- news.at1 (50%)
- ooe.arbeiterkammer.at1 (50%)