Menu
Browse

Cyber Incident Victim: InfraCom

Date

Sep 2024

Location

Sweden

Status

Unknown

Updated

2025-12-27 00:00

Timeline
Occurred
Sep 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

A ransomware attack targeted a limited portion of InfraCom's server environment, with swift detection via monitoring systems enabling rapid response. Recovery procedures restored over 95% of affected systems within two days, minimizing operational disruptions for customers. The primary confirmed impact stemmed from data exfiltrated by attackers, though the company refrained from commenting on datasets it did not own or manage as a data controller. Impacted customers received immediate notifications, followed by formal reporting to Sweden's privacy authority (IMY) and law enforcement. The organization subsequently collaborated with customers to enhance security awareness and developed tailored security packages to address evolving cyber risks.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

A ransomware attack occurred against InfraCom's server environment between the night of September 25 and 26, 2024, targeting a limited portion of their infrastructure. The intrusion was rapidly detected through the company's monitoring systems, triggering pre-established recovery protocols. Within 48 hours of the attack's initiation, InfraCom's operations team successfully restored over 95% of affected systems, enabling impacted customers to resume normal daily operations. While service disruptions were effectively contained, the attackers successfully extracted data during the breach. InfraCom maintained continuous dialogue with directly affected customers throughout the incident to manage operational consequences, though the company clarified it cannot comment on data it doesn't own or for which it isn't the personal data controller.

Cyber Incident Image

The primary confirmed impact stemmed from the data exfiltration rather than prolonged service interruptions. InfraCom promptly notified all affected customers following internal analysis of the incident and subsequently reported the breach to Sweden's Integrity Protection Authority (IMY) and law enforcement. The company developed security enhancement packages in collaboration with customers to address evolving cyber risks, concurrently initiating awareness campaigns to strengthen security practices. Media coverage generated inquiries from unaffected third parties without contractual relationships to InfraCom, prompting this public statement to address broader concerns. InfraCom expressed regret for the consequences of the attackers' actions while acknowledging its team's restoration efforts.

Sources
Sources available to members
1 source