Cyber Incident Victim: Geox
Date:
Jun 2020
Location:
Italy
Summary
An Italian footwear company experienced a ransomware attack that crippled headquarters systems for two days, disrupting logistics, e-commerce, and corporate email operations. The incident forced temporary employee furloughs while technicians worked to restore systems and eradicate the malware, though online order fulfillment and partner communications continued despite the compromise. This marked the organization's second cybersecurity incident within months, following a prior collaboration with postal police to dismantle a fraudulent impersonation website targeting customers. The company had maintained an established cybersecurity partnership with law enforcement for two years prior to these events.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around June 15, 2020, Italian footwear manufacturer Geox suffered a ransomware attack that crippled operations at its Montebelluna headquarters for two consecutive days. The attack deployed malware that encrypted data on infected machines, rendering systems inoperable without a decryption key typically offered by attackers in exchange for ransom payments. Critical business functions—including logistics operations, e-commerce platforms, and corporate email systems—were paralyzed. This disruption forced Geox to temporarily suspend onsite work and send employees home while internal technical teams focused on restoring systems and eradicating the ransomware. Despite the severe operational impact, the company maintained partial functionality by continuing to process online orders and preserve communications with retailers, customers, and suppliers throughout the incident.

This marked Geox's second cybersecurity incident within six months, following a May 2020 operation where the company collaborated with Italy's Postal Police to dismantle Geoxoutlet.online, a fraudulent website impersonating an official outlet store to sell non-existent products. The ransomware attack occurred amid Geox's established two-year cybersecurity partnership with law enforcement agencies, reflecting prior organizational recognition of digital threats. Technical response teams worked intensively to restore headquarters operations, though the article does not specify whether ransom demands were issued or paid. No data exfiltration or secondary impacts beyond operational disruption were reported. The incident underscored persistent vulnerabilities in corporate infrastructure despite proactive security measures and interagency cooperation.
