Menu
Browse

Cyber Incident Victim: Peikko Group

Date:

Dec 2024

Location:

Finland

Summary

Peikko Group experienced a cyber attack disrupting operations across multiple systems, including partial limitations to its Microsoft D365 ERP platform in 21 countries and temporary manual operations in some regions. Manufacturing and deliveries were initially impacted at several factories, though core tools like Peikko Designer® remained functional. The company reported potential unauthorized access to customer data, with the breach scope under investigation. Recovery efforts involved 24/7 restoration work with external experts, leading to a return to near-normal operations within approximately two weeks. Authorities were notified, and services stabilized with residual minor restoration activities having minimal operational impact.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Peikko Group experienced a cyber attack during the final weekend of December 2024, first publicly disclosed on December 30. The company immediately reported the incident to Finnish police, the National Cyber Security Centre, and other relevant authorities while collaborating with internal and external cybersecurity experts to investigate the scope. Initial operational impacts included partial disruption of manufacturing and delivery systems across Peikko’s 12 factories, though core communication channels (websites, emails, phones) and the Peikko Designer® tool remained functional. By December 31, recovery efforts confirmed limited manufacturing resumption in non-holiday factories and restored access to Tekla 3D modelling software and its cloud-based Tekla Model Sharing collaboration tool. The company disclosed preliminary evidence suggesting potential unauthorized access to or theft of customer-related data, though the full extent remained under investigation.

Cyber Incident Image

Restoration efforts intensified through early January 2025, with Peikko’s Microsoft Dynamics 365 ERP system operational across 21 countries by January 2, albeit with limited features, enabling manufacturing and product dispatch. Subsidiaries using older ERP systems operated normally, while others temporarily relied on manual processes. Round-the-clock recovery actions continued until January 6, when all factories resumed near-normal operations with minor residual restoration activities. Service capabilities were minimally affected during this final phase, with customers directed to local sales representatives for delivery inquiries. Peikko declared operations normalized on January 9, ceasing incident updates after confirming only negligible ongoing restoration impacts. The company maintained its commitment to transparency regarding data breach implications but provided no further public findings beyond acknowledging the attack’s conclusion.

Sources
Sources available to members
1 source