CSIDB logo
Incident

Glutz AG

Incident posture

Attack window
Nov 2022
Location
Switzerland
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Glutz AG
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted Glutz AG, prompting immediate notification of employees, customers, business partners, and authorities. Business operations and production continued with limitations throughout the incident, though the organization transitioned to restricted normal operations following security protocols and emergency measures. Investigative work by security agencies and IT forensics remained ongoing, with temporary operational constraints persisting in some areas but not affecting service quality for clients or partners. The company gradually resumed standard activities.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On November 28, 2022, Glutz AG experienced a cybersecurity incident as part of a broader wave of attacks targeting prominent companies. The organization publicly disclosed the event on the same day, promptly notifying employees, customers, business partners, and relevant authorities. Despite operational disruptions, Glutz maintained business continuity throughout the incident, with production and core functions continuing under constrained conditions. The company did not specify the attack vector or identity of threat actors in its communications. Immediate emergency measures were activated to contain the incident, though the nature of these technical countermeasures remained undisclosed.

By December 7, 2022—ten days after initial detection—Glutz restored limited normal operations through implemented security protocols and crisis management procedures. Forensic investigations involving law enforcement and cybersecurity specialists remained ongoing as of December 8, with no public conclusion timeline provided. Residual operational limitations persisted in unspecified business units, though the company emphasized these caused no qualitative impact on client services or partner deliverables. Glutz established a dedicated communication channel ([email protected]) for stakeholder inquiries regarding the incident. No data breach confirmation or ransomware claims appeared in the official statement, nor did the company disclose financial repercussions or production loss metrics.

Sources

Sources available to members: 1 source.

CSIDB