CSIDB logo
Incident

Geox

Incident posture

Attack window
Jun 2020
Location
Italy
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Geox
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

An Italian footwear company experienced a ransomware attack that crippled headquarters systems for two days, disrupting logistics, e-commerce, and corporate email operations. The incident forced temporary employee furloughs while technicians worked to restore systems and eradicate the malware, though online order fulfillment and partner communications continued despite the compromise. This marked the organization's second cybersecurity incident within months, following a prior collaboration with postal police to dismantle a fraudulent impersonation website targeting customers. The company had maintained an established cybersecurity partnership with law enforcement for two years prior to these events.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around June 15, 2020, Italian footwear manufacturer Geox suffered a ransomware attack that crippled operations at its Montebelluna headquarters for two consecutive days. The attack deployed malware that encrypted data on infected machines, rendering systems inoperable without a decryption key typically offered by attackers in exchange for ransom payments. Critical business functions—including logistics operations, e-commerce platforms, and corporate email systems—were paralyzed. This disruption forced Geox to temporarily suspend onsite work and send employees home while internal technical teams focused on restoring systems and eradicating the ransomware. Despite the severe operational impact, the company maintained partial functionality by continuing to process online orders and preserve communications with retailers, customers, and suppliers throughout the incident.

This marked Geox's second cybersecurity incident within six months, following a May 2020 operation where the company collaborated with Italy's Postal Police to dismantle Geoxoutlet.online, a fraudulent website impersonating an official outlet store to sell non-existent products. The ransomware attack occurred amid Geox's established two-year cybersecurity partnership with law enforcement agencies, reflecting prior organizational recognition of digital threats. Technical response teams worked intensively to restore headquarters operations, though the article does not specify whether ransom demands were issued or paid. No data exfiltration or secondary impacts beyond operational disruption were reported. The incident underscored persistent vulnerabilities in corporate infrastructure despite proactive security measures and interagency cooperation.

Sources

Sources available to members: 1 source.

CSIDB