The City of Vienna has disclosed that unauthorised attackers copied around 26,000 internal documents from its IT systems, including data relating to almost 6,000 people, according to the city's chief information security officer.

What makes the case notable is how it surfaced. Rather than being detected by the city's own monitoring, the breach came to light because the underlying vulnerability was offered for sale — a reminder that defenders increasingly learn about intrusions from criminal marketplaces and leak sites rather than their own alerts. It is the latest in a run of attacks on the Austrian capital; Austrian media have counted more than 20 break-ins in Vienna since the start of the year.

The stolen material is the familiar kind of municipal data: internal administrative documents rather than, apparently, a single trove of citizen records — but the disclosure that data on nearly 6,000 people is involved makes it a notifiable incident, with the accompanying duties to inform those affected and the data protection authority.

For other public bodies, the case is a compact lesson in modern breach economics. Municipal IT is a large, diverse and often under-resourced attack surface, and the value of a single exploitable flaw can be turned into cash immediately. A vulnerability therefore does not need to be actively used to be dangerous — it needs only to be discoverable and saleable. Detection, then, cannot stop at the perimeter: watching what is being sold on cybercrime forums is now part of finding out that you have already been breached.