Cyber Incident Victim: Olympus
Timeline
Summary
A leading medical technology company experienced a cybersecurity incident impacting limited areas of its Europe, Middle East, and Africa IT systems, specifically affecting sales and manufacturing networks. The BlackMatter ransomware group, linked to the DarkSide operation, was responsible for the attack, which prompted an immediate response involving forensic experts and suspension of data transfers in affected systems. While the incident was described as an attempted malware attack, the organization confirmed customer-facing security and services remained unaffected throughout the event.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On September 8, 2021, Olympus, a global medical technology firm with over 31,000 employees, detected suspicious activity affecting limited areas of its IT systems in the Europe, Middle East, and Africa (EMEA) region. The company initiated an investigation into what it described as a "potential cybersecurity incident," mobilizing a specialized response team that included forensics experts. Olympus suspended data transfers within the compromised systems as a containment measure and notified relevant external partners about the situation. The incident occurred three days before the company publicly acknowledged it on September 11, 2021. Christian Pott, an Olympus corporate spokesperson, emphasized that customer-facing security, support services, and product operations remained unaffected throughout the event. The company maintained that resolving the issue received the highest operational priority, though specific technical details about the intrusion vector or data compromise were not disclosed in initial statements.

Evidence linked the attack to the BlackMatter ransomware operation, based on ransom notes discovered during the investigation that directed victims to a Tor negotiation site previously associated with the group. BlackMatter had emerged in July 2021 as a new ransomware-as-a-service operation, with cybersecurity researchers initially speculating it represented a rebranding of the DarkSide gang following law enforcement pressure after the Colonial Pipeline attack. Forensic analysis later confirmed BlackMatter used identical custom encryption routines to DarkSide, supporting the connection between the groups. On September 14, 2021, Olympus updated its characterization of the event to an "attempted malware attack" that specifically impacted EMEA sales and manufacturing networks. The company did not confirm whether data exfiltration occurred or if ransom demands were paid, nor did it disclose operational downtime metrics. Manufacturing and sales network disruptions suggested potential indirect impacts on supply chain operations, though Olympus maintained public focus on containment and investigation progress rather than detailed consequence disclosure.
