Cyber Incident Victim: Marinomed Biotech AG
Date:
Nov 2025
Location:
Austria
Summary
Marinomed Biotech AG announced it was victim of cybercrime that resulted in an unauthorized transfer of approximately EUR 677,000 to parties outside the European Economic Area. The company filed criminal charges with authorities, engaged external advisors to investigate, and is assessing whether its insurance policies will cover the loss. Attempts to reverse the transaction or block the funds at the recipient bank have so far failed, but the management board states that liquidity remains secure.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Marinomed Biotech AG, headquartered in Korneuburg, Niederösterreich, announced on April 1 2025 that it had become the victim of a cybercrime incident. The attack resulted in an unauthorized outflow of funds amounting to approximately EUR 677,000, which was transferred to third parties located outside the European Economic Area. The company disclosed the incident publicly and filed criminal charges with the relevant investigating authorities. The announcement was made via an ad‑hoc notice and reported by local media outlets.

In response, Marinomed engaged external advisors to conduct a full clarification of the event and to determine the precise circumstances surrounding the fraudulent transfer. Simultaneously, the company began reviewing its existing insurance policies to assess whether any potential damages could be covered under those provisions. Despite ongoing efforts, attempts to reverse the transaction or to block the transferred funds at the recipient bank have so far been unsuccessful. The company continues to cooperate with law enforcement and its advisors to resolve the matter.
At the time of the announcement, Marinomed’s Management Board stated that the company’s liquidity remains secured despite the financial loss. No further details about compromised systems, attacker identity, or specific detection methods were disclosed in the available sources. The incident remains under investigation, and the company is monitoring any developments related to the case.
