CSIDB logo
Incident

Tarkett

Incident posture

Attack window
Apr 2020
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
Tarkett
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A French flooring manufacturer experienced a significant cyber attack that disrupted portions of its operations, prompting immediate system shutdowns and preventive measures to safeguard employee, customer, and partner data. The company mobilized internal teams alongside external IT experts and forensic specialists to restore normal operations while commercial and production activities remained impaired. Authorities were engaged regarding the incident, with cybersecurity insurers also notified as part of the response efforts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 29, 2020, French flooring manufacturer Tarkett experienced a cyber attack that disrupted portions of its business operations. The company confirmed the incident publicly, acknowledging that its existing IT security measures had been compromised. In immediate response to the breach, Tarkett initiated a system-wide shutdown of its information technology infrastructure to contain the incident. This action formed part of broader preventive measures implemented to safeguard operational continuity and protect sensitive data belonging to employees, customers, and business partners. The attack caused sustained disruptions to both commercial activities and manufacturing processes, though the company did not specify which facilities, departments, or technical systems were most severely impacted. Tarkett's crisis management protocol included engagement with external cybersecurity specialists and forensic investigators to analyze the breach.

Tarkett's internal teams worked continuously alongside third-party IT experts to restore normal operations, though commercial and production activities remained impaired during the recovery phase. The organization maintained communication with unspecified regulatory or law enforcement authorities regarding the incident and formally notified its cybersecurity insurance provider about the attack. No technical details about the attack vector, malware type, or threat actor were disclosed publicly. The company emphasized its focus on securing systems and data while working to resume full operational capacity, without providing a projected timeline for complete recovery. Tarkett's statement confirmed the attack's operational consequences persisted beyond the initial containment efforts, though it did not quantify financial losses, data compromise specifics, or duration of service interruptions.

Sources

Sources available to members: 1 source.

CSIDB