CSIDB logo
Incident

InfraCom

Incident posture

Attack window
Sep 2024
Location
Sweden
Status
Historical
CIA posture
Available to members
Updated
2025-12-27 00:00

Linked entities

Victim
InfraCom
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted a limited portion of InfraCom's server environment, with swift detection via monitoring systems enabling rapid response. Recovery procedures restored over 95% of affected systems within two days, minimizing operational disruptions for customers. The primary confirmed impact stemmed from data exfiltrated by attackers, though the company refrained from commenting on datasets it did not own or manage as a data controller. Impacted customers received immediate notifications, followed by formal reporting to Sweden's privacy authority (IMY) and law enforcement. The organization subsequently collaborated with customers to enhance security awareness and developed tailored security packages to address evolving cyber risks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A ransomware attack occurred against InfraCom's server environment between the night of September 25 and 26, 2024, targeting a limited portion of their infrastructure. The intrusion was rapidly detected through the company's monitoring systems, triggering pre-established recovery protocols. Within 48 hours of the attack's initiation, InfraCom's operations team successfully restored over 95% of affected systems, enabling impacted customers to resume normal daily operations. While service disruptions were effectively contained, the attackers successfully extracted data during the breach. InfraCom maintained continuous dialogue with directly affected customers throughout the incident to manage operational consequences, though the company clarified it cannot comment on data it doesn't own or for which it isn't the personal data controller.

The primary confirmed impact stemmed from the data exfiltration rather than prolonged service interruptions. InfraCom promptly notified all affected customers following internal analysis of the incident and subsequently reported the breach to Sweden's Integrity Protection Authority (IMY) and law enforcement. The company developed security enhancement packages in collaboration with customers to address evolving cyber risks, concurrently initiating awareness campaigns to strengthen security practices. Media coverage generated inquiries from unaffected third parties without contractual relationships to InfraCom, prompting this public statement to address broader concerns. InfraCom expressed regret for the consequences of the attackers' actions while acknowledging its team's restoration efforts.

Sources

Sources available to members: 1 source.

CSIDB