started · updated
KVV-Gruppe websites targeted by cyberattack in Kassel
The KVV-Gruppe, a utility and transport company in Kassel, Germany, has experienced a cyberattack involving malicious code embedded in several of its websites. The affected domains include kvvks.de, kvg.de, netzplussservice.de, and various pages related to local baths.
Visitors to these sites may have been prompted to perform fraudulent installations or changes to their computers, potentially loading malware onto their devices. While the exact number of affected users remains unclear, the company stated that its core IT systems and customer data do not appear to be compromised based on internal investigations.
In response, KVV has reduced its web presence to essential contact information and is working with external IT forensics experts to investigate how the manipulation occurred. The company has also notified the Federal Office for Information Security (BSI) and Hessian data protection authorities.