Menu
Browse

Cyber Incident Victim: Griesser AG

Date:

Apr 2021

Location:

Switzerland

Summary

A Swiss manufacturer of window treatments experienced a ransomware attack targeting its servers, disrupting operations at production facilities in Switzerland, Austria, and France. The company's IT task force proactively shut down multiple systems to contain the incident while internal and external experts investigated under high pressure. Communication with partners and customers was limited to phone and email during the disruption. The organization stated it was prepared for such scenarios but did not confirm whether customer, partner, or employee data was compromised. No details regarding the ransomware variant or potential ransom demands were disclosed.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around April 14, 2021, Griesser AG, a Swiss manufacturer of sun protection window treatments including blinds, shutters, and awnings, suffered a ransomware attack targeting its servers. Unknown perpetrators deployed ransomware, described as a "blackmail Trojan," affecting the company's primary operations in Aadorf, Switzerland, as well as production facilities in Austria and France. The attack disrupted normal business operations, forcing Griesser AG to limit communications to phone and email channels only. Upon detecting the incident, the company's IT task force immediately shut down multiple IT systems to contain the attack and prevent further propagation across the network. This containment measure was implemented as a precautionary step, though it likely contributed to operational disruptions.

Cyber Incident Image

Griesser AG publicly acknowledged the incident through a statement on its website, informing customers and partners about the situation and providing alternative contact methods. The company emphasized its preparedness for such scenarios, noting that a dedicated task force of internal and external experts had been mobilized to conduct a detailed investigation. Specialists worked under high pressure to resolve the IT incident, though the timeline for full restoration remained unspecified. At the time of reporting, Griesser AG had not confirmed whether customer, partner, or employee data was exfiltrated during the attack. Neither the company nor initial media disclosures identified the specific ransomware variant involved or indicated whether a ransom demand was issued. The investigation remained ongoing, with updates contingent on further findings by the task force.

Sources
Sources available to members
1 source