8:15pm. In a final statement, Post announces the gradual restoration of its services. “An absolute priority has been given to restoring calls to emergency services: these are now fully operational throughout the country, via both the fixed and mobile networks. Post’s technical teams are fully mobilised and are continuing their efforts to restore all services as quickly as possible.”
Almost an hour later, the High Commission for National Protection (HCPN) sent its own update on the situation, just to show that the government was fully mobilised to remedy the internet outage, both fixed and mobile, which began to affect the country at around 4.15pm. “Following the disruption to Post’s communication networks (internet, mobile and fixed-line) that affected the whole country at around 4.15pm, the prime minister convened a crisis unit. This, chaired by the minister for the economy, SMEs, energy and tourism, Lex Delles, and in the presence of the minister for home affairs,
Léon Gloden, met in the early evening to analyse the situation and discuss any additional appropriate measures that might be required,” it reads.
At around 6.30pm, smartphones started ringing and receiving text messages from the Luxembourg alert system, sying that “in case of emergency and unable to access 112 by phone, try another operator. Otherwise, go to the nearest emergency room or fire station.” In its press release, the HCPN explains that “as a result of these disruptions, alerts broadcast by the LU-Alert system were disclosed out of phase to customers of the Post operator.” It’s a sentence that could have very different meanings, from its temporal aspect (too late in relation to the start of the sequence) to its causal aspect (because the technology would have escaped the control of the person who normally uses it).
If we are to understand “too late,” we also understand that the communication is to the millimetre which gives no explanation of the origin of the problem and avoids any superfluous words. It’s almost a masterpiece of crisis communication in the event of a cyber attack. The origin of the problem is not given, even though Post’s experts know perfectly well if a device is down, and no publicity is given to those who may have attacked the company so that they cannot congratulate themselves publicly.
Two things support this hypothesis: according to Cloudflare statistics, cyberattacks have started to become more numerous since 20 July, and exceeded the average from Tuesday evening onwards, remaining well above the weekly statistics all day yesterday; then, on their characteristics, distributed denial-of-service (or DDOS) attacks, which average around 38% of the weekly number, reached as high as 88% at midnight on Wednesday night.
One of the most common strategies used by hackers is to flood the computer servers of certain companies or administrations with requests in the millions so that the servers, unable to respond to everyone at once, prefer to shut down, leading to computer “blackouts” of varying sizes, depending on the organisation and the country. This is what happened to Luxembourg in March 2024, when pro-Russian hackers claimed responsibility for the attacks in protest at Luxembourg’s support for Ukraine.
Last Wednesday, the Ukrainian energy minister thanked Luxembourg for an additional €12m in the special energy fund and the government issued two press releases on additional sanctions against Russian interests and its position on frozen assets in the context of Russia's invasion of Ukraine.
These are the kinds of things that “invite” hackers to act. A Europol and Eurojust operation in mid-July targeted hackers in an operation dubbed Eastwood, which aimed to dismantle--albeit very partially--the cybercrime network Noname057, which claimed responsibility for the first attack in Luxembourg. “In total, national authorities have issued seven arrest warrants, which are directed, inter alia, against six Russian nationals for their involvement in the Noname057(16) criminal activities. All of the suspects are listed as internationally wanted, and in some cases, their identities are published in media. Five profiles were also published on the EU Most Wanted website.”
However, that these networks are highly decentralised and have--according to the experts who want to sell their cybersecurity solutions--from 6,000 to 35,000 more or less active sympathisers, capable of coordinating to launch request packets at well-established targets.
This article was originally published in French.



