CSIDB logo
Incident

Swisspro Group AG

Incident posture

Attack window
Apr 2024
Location
Switzerland
Status
Historical
CIA posture
Available to members
Updated
2026-01-01 03:42

Linked entities

Victim
Swisspro Group AG
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted the legacy IT infrastructure of a BKW subsidiary, though current operational systems across the organization and its affiliated companies remained unaffected, allowing continued customer service delivery. A taskforce was established to contain the incident, promptly informing authorities, isolating compromised systems, and enforcing password changes. Monitoring confirmed no signs of subsequent attacks on customer systems or other entities within the corporate group, while analysis regarding potential data exfiltration remains ongoing.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early April 2024, Swisspro—a subsidiary of Swiss energy company BKW—experienced a ransomware attack targeting its legacy IT infrastructure. The incident was confirmed by BKW’s media office, which clarified that the attack specifically affected Swisspro’s outdated systems but did not compromise the operational IT environments of Swisspro, BKW Building Solutions, or other entities within the BKW group. Swisspro maintained its ability to deliver customer services throughout the incident. Authorities were notified immediately, and a dedicated taskforce was established to investigate the attack’s scope, contain potential impacts, and implement countermeasures. The taskforce isolated the compromised systems and enforced password changes as initial containment steps. BKW emphasized that its broader infrastructure operated normally, with continuous monitoring for anomalies, and stated there was no evidence of follow-on attacks targeting customer systems or other BKW subsidiaries, including UMB and affiliated companies merged under BKW Building Solutions in 2022.

The attack occurred against a backdrop of organizational consolidation, as Swisspro Solutions, Alphatrust, and Ngworx had been integrated into UMB under BKW’s ownership two years prior. Forensic analysis to determine whether data exfiltration occurred remained ongoing at the time of reporting. BKW’s public statements focused on minimizing operational disruption, reiterating that the ransomware’s impact was confined to Swisspro’s legacy architecture and did not propagate to active networks. No ransomware group or specific attack vector was identified in the available disclosures. The company did not disclose whether ransom demands were issued or if data restoration efforts were underway. All response actions were coordinated through the taskforce, with no further technical details or timelines for resolution provided.

Sources

Sources available to members: 1 source.

CSIDB