What measures have been taken?
Based on the initial suspicion, the Office of Information Technology immediately implemented measures to secure the data and took the affected system offline. At the same time, a comprehensive analysis of the incident was initiated. On 31 July 2026, the Government was informed that a potentially successful attack on the VwbP had taken place. On the afternoon of 1 August 2026, the first confirmed results of the preliminary investigations were transmitted to the Government.
On Friday, 31 July 2026, the eMWST portal for value added tax and the electronic reporting and data exchange platform Lides had already been taken offline. On Monday, 3 August 2026, the Central Register of Accounts and the central tax administration system Intax followed. These are purely precautionary measures. There is no indication that unlawful access took place in these systems. All systems are now undergoing additional comprehensive security checks.
Over the weekend, the Office of Justice filed a criminal complaint against persons unknown. The prosecution authorities then immediately took up their investigations. Digital traces are being analysed and followed up in cooperation with European authorities.