Stadt Wien discloses 26,000 documents copied from an internal documentation platform; Austria's CERT.at reported a forum offer to buy a vulnerability in a city system
Vienna says a CERT.at tip about a forum bid for a vulnerability led to its probe of 26,000 copied documents
Analysis
Stadt Wien's own press release of 2026-09-30 says an attacker had web access to parts of an internal documentation platform of the city administration between 2026-09-03 and 2026-09-11 and copied internal content, in particular test data, training material and project documentation (Stadt Wien, 2026-09-30). The copied set is about 26,000 documents and pages, roughly nine gigabytes, and includes personal data, which may in places be special categories under the GDPR, plus business and infrastructure information (Stadt Wien, 2026-09-30). The investigation started when CERT.at flagged on 2026-09-09 an offer in an online forum to buy a vulnerability in a technical system of the city; the city's WienCERT and its IT department then analysed the system and, with the Directorate for State Protection and Intelligence, identified and closed the flaw (Stadt Wien, 2026-09-30). The city filed a voluntary incident report under the Austrian NIS Act on 2026-09-10 and the statutory data-protection report on 2026-09-15, and will notify 2,885 citizens, 2,083 employees and 856 contractors within a week; its CIO says the attacker never controlled IT systems or user accounts and that no indication of publication exists (Stadt Wien, 2026-09-30). The release names no product, no flaw and no actor, and public disclosure came 19 days after the access window ended.
Exposure: any internal documentation, wiki or project platform of an administration that is reachable through a web access path; the city says the copied content included technical documentation, personal data and business and infrastructure information, so what the platform stores matters as much as its patch state.
Cited evidence
The trigger for the current investigation was a tip from the Austrian Computer Emergency Response Team (CERT.at) on 9 September 2026 about an offer in an online forum to buy a vulnerability in a technical system of the City of Vienna. (translated from German)
an attacker had access to parts of an internal documentation platform of the Magistrat via web access between 3 September and 11 September 2026 (translated from German)
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.