Menu
Browse

Cyber Incident Victim: Marinomed Biotech AG

Date:

Nov 2025

Location:

Austria

Summary

Marinomed Biotech AG announced it was victim of cybercrime that resulted in an unauthorized transfer of approximately EUR 677,000 to parties outside the European Economic Area. The company filed criminal charges with authorities, engaged external advisors to investigate, and is assessing whether its insurance policies will cover the loss. Attempts to reverse the transaction or block the funds at the recipient bank have so far failed, but the management board states that liquidity remains secure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Marinomed Biotech AG, headquartered in Korneuburg, Niederösterreich, announced on April 1 2025 that it had become the victim of a cybercrime incident. The attack resulted in an unauthorized outflow of funds amounting to approximately EUR 677,000, which was transferred to third parties located outside the European Economic Area. The company disclosed the incident publicly and filed criminal charges with the relevant investigating authorities. The announcement was made via an ad‑hoc notice and reported by local media outlets.

Cyber Incident Image

In response, Marinomed engaged external advisors to conduct a full clarification of the event and to determine the precise circumstances surrounding the fraudulent transfer. Simultaneously, the company began reviewing its existing insurance policies to assess whether any potential damages could be covered under those provisions. Despite ongoing efforts, attempts to reverse the transaction or to block the transferred funds at the recipient bank have so far been unsuccessful. The company continues to cooperate with law enforcement and its advisors to resolve the matter.

At the time of the announcement, Marinomed’s Management Board stated that the company’s liquidity remains secured despite the financial loss. No further details about compromised systems, attacker identity, or specific detection methods were disclosed in the available sources. The incident remains under investigation, and the company is monitoring any developments related to the case.

Sources
Sources available to members
2 sources