CSIDB logo
Incident

Jakob Becker GmbH & Co. KG

Incident posture

Attack window
May 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
Jakob Becker GmbH & Co. KG
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted a German waste management company, severely disrupting its operations and communication systems including telephone and email services. The incident forced the organization to halt normal business activities, with management expressing hopes for restored functionality while authorities investigated the breach. Police involvement confirmed the criminal nature of the attack, which caused prolonged operational paralysis affecting customer interactions and internal processes.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 24, 2022, Jakob Becker GmbH & Co. KG, a waste management company based in Mehlingen, Germany, experienced a disruptive cyberattack targeting its IT infrastructure. The attack rendered critical communication systems inoperable, including email and telephone services, severely hampering internal operations and customer interactions. Employees were forced to rely on manual workarounds such as handwritten notes to maintain basic service continuity during the outage. The company's managing director, Thomas Pfaff, publicly acknowledged the incident and indicated recovery efforts were underway. The attack caused sustained operational paralysis, with systems remaining offline for multiple days.

The company prioritized restoring customer-facing communications, with Pfaff stating the goal was to regain normal service accessibility for clients as soon as possible. The disruption affected approximately 2,000 customers and business partners, necessitating alternative coordination methods during the outage. Local law enforcement initiated an investigation into the attack, though no attribution or specific attack vector was disclosed publicly. Operational impacts included delayed administrative processes and reliance on non-digital workflows until systems could be fully restored. The incident underscored the vulnerability of critical infrastructure providers to cyber disruptions affecting core business functions.

Sources

Sources available to members: 1 source.

CSIDB