Cyber Incident Victim: AddComm
Date:
May 2024
Location:
Netherlands
Summary
AddComm experienced a ransomware attack where cybercriminals gained unauthorized access to customer data, encrypted internal systems, and exfiltrated information, resulting in prolonged service disruptions. The organization engaged external cybersecurity experts to restore operations and conduct forensic investigations, confirming attackers no longer have system access. While specifics of compromised customer data remain undetermined, the breach did not impact clients' own systems. Legal authorities are being notified as part of the ongoing response to the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
AddComm experienced a ransomware attack between May 5 and May 17, 2024, with the intrusion culminating in system encryption on May 17 that alerted the organization to the breach. Cybercriminals gained unauthorized access to customer data, encrypted internal systems, and exfiltrated information during the two-week compromise period. The attack rendered AddComm's systems inoperable for multiple days, preventing customer access to services. Upon detecting the encryption activity on May 17, AddComm immediately engaged external cybersecurity experts to conduct forensic analysis alongside their internal IT team. Restoration efforts prioritized security, with systems gradually returning to operation and customers being reconnected through controlled reactivation procedures.

The confirmed impacts included temporary service disruption, confirmed data theft of unspecified customer information, and system unavailability lasting several days. AddComm initiated a police report following the incident but could not specify which customers or datasets were affected by the theft. The attackers were successfully expelled from systems, with no evidence of compromise spreading to customer-owned infrastructure. Ongoing forensic work continues to investigate the attack vector and full data exposure scope. AddComm established a dedicated customer inquiry channel ([email protected]) while publicly acknowledging the incident and apologizing for operational disruptions. No ransom payment details or attacker identities were disclosed in available information.
