CSIDB logo
Incident

Swiss Cloud Computing AG

Incident posture

Attack window
Apr 2021
Location
Switzerland
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Swiss Cloud Computing AG
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted Swiss Cloud Computing AG, disrupting services for approximately 6,500 customers of the Swiss cloud provider. The company engaged specialists from HPE and Microsoft to restore affected servers through continuous shift work, aiming to resume operations the following week. During restoration efforts, the firm's website remained inaccessible, with updates on progress promised after intensive recovery activities.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Swiss Cloud Computing AG, a provider of cloud services for independent software vendors and ICT resellers in Switzerland, experienced a ransomware attack in late April 2021. The attack occurred approximately one week before April 27, when media coverage first emerged, though the exact intrusion timeline remains unspecified in available reports. The incident disrupted the company's operations and affected approximately 6,500 customers who relied on its cloud infrastructure. While the ransomware variant was not publicly identified, the attack caused significant service outages that rendered Swiss Cloud's website inaccessible to external visitors at the time of initial reporting. The company acknowledged the breach through public statements, confirming the involvement of ransomware but withholding technical details about the attackers' methods or any ransom demands.

Swiss Cloud Computing AG initiated recovery efforts immediately following the attack, engaging specialists from Hewlett Packard Enterprise (HPE) and Microsoft to assist with server restoration. Restoration work continued through the weekend of May 1-2 in 24-hour shifts, with the company committing to provide further status updates by Monday, May 3. The organization projected service restoration for the week beginning May 3, though no specific completion date was confirmed in the available reporting. Customer impact persisted throughout the outage period, with no details provided about data compromise beyond service disruption. The company's public communications focused exclusively on technical recovery efforts, without disclosing operational contingency measures or forensic findings regarding the attack's origin. Service availability remained partially impaired as of April 27, evidenced by the continued inability to access Swiss Cloud's primary website.

Sources

Sources available to members: 1 source.

CSIDB