this post was submitted on 14 Jul 2026
27 points (100.0% liked)

Privacy

4849 readers
217 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
 

In a notice to customers and suppliers, the organization said it had exhausted every available option before seeking insolvency protection. Managing director Johannes Zenglein described the filing as "one of the most difficult steps in our company's 37-year history." "The cyberattack of March 29, 2026, however, impacted our company to an extent that we could not fully compensate for despite our best efforts," Zenglein wrote. "The consequences resulted in a production outage of nearly six weeks and significant financial strain. These effects ultimately impacted our financial situation so severely that filing for insolvency became necessary."

Wow.

ZEGO did not disclose what kind of attack it suffered, whether ransomware was involved, who was behind it, or whether customer or employee data was compromised.

Wait a minute... ಠಿ⁠_⁠ಠ

top 5 comments
sorted by: hot top controversial new old
[–] aarch0x40@piefed.social 14 points 1 week ago* (last edited 1 week ago)

iow, "We got so comfortable in our operation that we never even considered the digital security of our business or customers".

ZEGO did not disclose what kind of attack it suffered, whether ransomware was involved, who was behind it, or whether customer or employee data was compromised.

I wonder if they even understand the scope of the compromise. They clearly cut corners on business continuity insurance. It wouldn't be surprising at all if the breach fried all their equipment (like stuxnet). Their systems were probably on or adjacent to internet routes.

[–] Ludicrous0251@piefed.zip 9 points 1 week ago (1 children)

6 weeks offline is rough, but not "shutter an otherwise totally profitable business" bad, especially not one that's allegedly had 37 years to save up for an outage and/or discover the wide world of business insurance.

Something tells me the poor IT security was just the tip of the iceberg on a looong list of missteps.

[–] zqps@sh.itjust.works 3 points 1 week ago

You can't get insured for this without already having robust IT security in place. Both are viewed as a largely pointless expense by far too many old C-Level suits (who will make off with a neat bonus for their failure).

[–] onlinepersona@programming.dev 7 points 1 week ago

ZEGO did not disclose what kind of attack it suffered, whether ransomware was involved, who was behind it, or whether customer or employee data was compromised

GDPR states that if personally identifying information was compromised, the users must be notified. They can't just decide not to publish what happened. It's against the law.

This screams "upper management didn't make security a priority".

[–] mastod0n@lemmy.world 1 points 1 week ago

I don't buy it.