CSIDB logo
Incident

Semikron

Incident posture

Attack window
Aug 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
Semikron
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Aug 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Semikron, a global semiconductor manufacturer, experienced a ransomware attack by the LV group, resulting in partial encryption of IT systems and claims of 2TB data exfiltration. The company engaged external cybersecurity and forensic experts to investigate the breach while collaborating with authorities; affected customers and partners would be notified if data theft was confirmed. Restoration efforts focused on minimizing operational disruptions and enhancing IT security measures across its international offices and production sites.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around August 1, 2022, the Semikron Group, a German power electronics manufacturer with global operations across 24 offices and 8 production sites, experienced a ransomware attack attributed to a professional hacker group. The attackers deployed LV ransomware, partially encrypting the company's IT systems and files while claiming to have exfiltrated approximately 2TB of documents prior to encryption. Semikron disclosed the incident through an official statement on August 1, confirming network compromise and ongoing forensic analysis. The German Federal Office for Information Security (BSI) corroborated the attackers' blackmail attempts, including threats to leak stolen data unless ransom demands were met. With annual revenues exceeding $461 million and technology embedded in 35% of global wind turbine installations, the incident posed operational and reputational risks to critical infrastructure supply chains.

Semikron immediately engaged external cybersecurity and forensic experts to investigate the scope of encryption and validate data theft claims, while coordinating with relevant authorities. The company prioritized restoring operational capabilities to minimize disruptions for employees, customers, and partners, though specific affected systems were not detailed beyond references to partial network encryption. Management established a dedicated email channel ([email protected]) for incident-related inquiries and committed to notifying stakeholders if evidence of data compromise emerged. No ransomware payment status or data leak confirmation was disclosed during the initial response phase. Recovery efforts focused on system remediation and security hardening, with ongoing collaboration between internal teams, external experts, and law enforcement agencies to address forensic findings and operational impacts.

Sources

Sources available to members: 2 sources.

CSIDB