CSIDB logo
Incident

Olympus

Incident posture

Attack window
Sep 2021
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2026-07-16 08:12

Linked entities

Victim
Olympus
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A leading medical technology company experienced a cybersecurity incident impacting limited areas of its Europe, Middle East, and Africa IT systems, specifically affecting sales and manufacturing networks. The BlackMatter ransomware group, linked to the DarkSide operation, was responsible for the attack, which prompted an immediate response involving forensic experts and suspension of data transfers in affected systems. While the incident was described as an attempted malware attack, the organization confirmed customer-facing security and services remained unaffected throughout the event.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 8, 2021, Olympus, a global medical technology firm with over 31,000 employees, detected suspicious activity affecting limited areas of its IT systems in the Europe, Middle East, and Africa (EMEA) region. The company initiated an investigation into what it described as a "potential cybersecurity incident," mobilizing a specialized response team that included forensics experts. Olympus suspended data transfers within the compromised systems as a containment measure and notified relevant external partners about the situation. The incident occurred three days before the company publicly acknowledged it on September 11, 2021. Christian Pott, an Olympus corporate spokesperson, emphasized that customer-facing security, support services, and product operations remained unaffected throughout the event. The company maintained that resolving the issue received the highest operational priority, though specific technical details about the intrusion vector or data compromise were not disclosed in initial statements.

Evidence linked the attack to the BlackMatter ransomware operation, based on ransom notes discovered during the investigation that directed victims to a Tor negotiation site previously associated with the group. BlackMatter had emerged in July 2021 as a new ransomware-as-a-service operation, with cybersecurity researchers initially speculating it represented a rebranding of the DarkSide gang following law enforcement pressure after the Colonial Pipeline attack. Forensic analysis later confirmed BlackMatter used identical custom encryption routines to DarkSide, supporting the connection between the groups. On September 14, 2021, Olympus updated its characterization of the event to an "attempted malware attack" that specifically impacted EMEA sales and manufacturing networks. The company did not confirm whether data exfiltration occurred or if ransom demands were paid, nor did it disclose operational downtime metrics. Manufacturing and sales network disruptions suggested potential indirect impacts on supply chain operations, though Olympus maintained public focus on containment and investigation progress rather than detailed consequence disclosure.

Sources

Sources available to members: 1 source.

CSIDB