Menu
Browse

Cyber Incident Victim: Omnicom Media Group

Date:

Feb 2021

Location:

United States of America

Summary

Omnicom Media Group experienced a cyber attack causing IT network disruptions, primarily impacting some of its non-US agencies. The company engaged third-party experts to investigate the incident and asserted no data was compromised. While the attack led to operational interruptions, normal business activities continued with progress reported in restoring affected systems. The organization maintained confidence in its recovery efforts and system integrity throughout the incident response.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On or around February 15, 2021, Omnicom Media Group (OMG) publicly confirmed a cyber incident that caused disruptions to portions of its IT network. The company detected IT network disturbances in the days preceding the announcement, though the exact date of initial compromise remains unspecified in available reports. OMG characterized the event as a "cyber incident" but did not disclose technical details regarding attack vectors, malware variants, or threat actor attribution. The disruption primarily impacted OMG's agencies operating outside the United States, though the company maintained that domestic operations continued without significant interruption. In response to the incident, OMG engaged third-party cybersecurity experts to investigate the nature and scope of the network disruption. The organization publicly asserted confidence that no sensitive data was compromised during the breach, though no supporting evidence or audit methodology was provided to substantiate this claim.

Cyber Incident Image

OMG implemented immediate containment measures while maintaining business continuity across its global operations. The company reported making "significant progress" toward restoring full functionality to affected systems by the time of its public disclosure on February 15. No ransomware notes, data exfiltration evidence, or extortion demands were referenced in available reporting. The incident response focused on system restoration rather than forensic analysis in public communications. Marketing-Interactive attempted to obtain additional details from OMG, but no supplemental information was released beyond the initial statement. Business operations continued throughout the remediation process with acknowledged interruptions limited to non-US agency functions. The company did not disclose whether the incident triggered regulatory notifications or client advisories under data protection laws.

Sources
Sources available to members
1 source