IMI
Incident posture
Timeline
Summary
The British engineering company IMI disclosed a cyber incident to the London Stock Exchange after detecting unauthorized access to its systems. Based in Birmingham, the firm specializes in industrial automation and climate control products and holds a substantial market capitalization. Upon discovering the intrusion, IMI engaged external cybersecurity experts to investigate and contain the incident. A company spokesperson declined further comment on the nature or scope of the event. This disclosure followed a similar report from another U.K. engineering firm, Smiths Group, which detected unsanctioned activity on its network about a week earlier. The incidents are part of a broader trend of cyber threats targeting European manufacturing and industrial sectors, which have faced hundreds of ransomware and industrial control system attacks in recent quarters.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
IMI, a Birmingham-based British engineering company specializing in industrial automation and climate control products, disclosed a cyber incident to the London Stock Exchange. According to a notification issued to the exchange, as of Thursday the company became aware of an incident involving unauthorized access to its systems. The notification described the event as "unauthorised access to the Company's systems" and confirmed that IMI began responding immediately upon detection. At the time of disclosure, the company held a market capitalization of $6.24 billion, underscoring the scale of the organization affected by the unauthorized activity.
Upon becoming aware of the intrusion, IMI engaged external cybersecurity experts to investigate and contain the incident. The company did not provide additional technical details about the nature of the attack, the systems impacted, or whether any data was accessed or exfiltrated. A spokesperson for IMI declined to comment further on the incident beyond the regulatory disclosure, leaving many specifics about the intrusion undisclosed to the public. The notification to the London Stock Exchange represented the company's primary formal communication regarding the security event.
The IMI disclosure followed a closely related incident involving another major U.K. engineering firm. On January 28, Smiths Group, a U.K.-based engineering company, told the London Stock Exchange that it had detected unsanctioned activity on its network. Smiths Group stated that it had rapidly isolated affected systems and activated its business continuity plans in response to the detected activity. The proximity of these two disclosures — within nine days of each other — drew attention to a pattern of cybersecurity events affecting major British engineering firms during late January and early February 2025. IMI's notification marked the second such incident reported by a U.K. engineering giant in that short timeframe, though no connection between the two events was established or suggested in available reporting.
The broader context for the IMI incident includes documented trends in cyberattacks targeting European industrial and manufacturing organizations. According to industrial cybersecurity company Dragos, there were 119 ransomware incidents targeting European companies in the third quarter of 2024 alone. Within Europe, the United Kingdom, Germany, and Italy were identified as the most affected countries during that period. Globally, Dragos reported 394 attacks on the manufacturing sector between July and September 2024, along with 56 incidents specifically affecting industrial control systems. These figures illustrated the heightened threat environment facing industrial firms, including those operating in the engineering sector.
A prior example of the impact such attacks could have on industrial companies involved the German belt drive manufacturer Arntz Optibelt Group, which was hit with a ransomware attack in August 2024. Dragos reported that this incident "significantly impacted the company's ability to conduct normal business operations," demonstrating the operational consequences that ransomware events could pose to manufacturers and engineering firms. While the available reporting on the IMI incident did not specify whether ransomware was involved in the unauthorized access, the broader threat landscape highlighted the risks facing companies with similar operational profiles and geographic footprints. IMI's specialization in industrial automation and climate control products placed it within sectors that had been frequent targets of cyber actors seeking to disrupt or compromise industrial operations.
The company's formal response, as outlined in its disclosure, centered on engaging external cybersecurity specialists to conduct an investigation and implement containment measures. The notification to the London Stock Exchange served as the company's primary public acknowledgment of the incident, fulfilling regulatory obligations while providing limited operational detail. No timeline for the full investigation, restoration of affected systems, or resolution of the incident was disclosed in the available reporting. The article documenting the disclosure was published on February 1, 2025, with IMI's notification to the exchange confirming the incident was active and being addressed as of the preceding Thursday.
Sources
Sources available to members: 1 source.