Menu
Browse

Cyber Incident Victim: BECOM Group

Date:

Apr 2024

Location:

Austria

Summary

BECOM Electronics experienced a cyberattack that was halted before encryption or significant damage occurred. The company promptly restricted internet access and limited communication channels to contain the incident. Production operations were disrupted, requiring intensive recovery efforts with assistance from three external specialists. Priority is currently on restoring manufacturing capabilities across all facilities while maintaining restricted external communications during the remediation process.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The cyber incident targeting BECOM Electronics occurred on Tuesday, 23 April 2024, as first reported by Austrian media outlet ORF. The attack involved unauthorized access to the company's systems, though management intervened swiftly to sever network connections before ransomware or other encryption mechanisms could be deployed. Upon detecting the intrusion, BECOM implemented immediate containment measures by restricting all internet connectivity across its operations to isolate compromised systems and prevent further attacker lateral movement. The company publicly confirmed these actions through a customer notification on 17 April 2024, four days after the initial attack, emphasizing that no data encryption had occurred during the breach. Production systems across BECOM's manufacturing facilities were forcibly taken offline as part of the containment strategy, causing operational disruption at multiple company locations.

Cyber Incident Image

BECOM's incident response prioritized restoring production capabilities, with management dedicating all available internal resources and engaging three external cybersecurity specialists to assist recovery efforts. The internet restrictions remained in place during the restoration phase, significantly limiting standard communication channels including email and web services. Company leadership explicitly stated they could not respond to partner inquiries due to concentrating personnel on remediation tasks. No data theft, financial impacts, or specific attacker identities were disclosed in available communications. The restoration timeline remained undefined as of the latest 1 April 2024 website statement, which reiterated ongoing efforts to methodically reactivate production environments while maintaining security controls. Business continuity measures focused exclusively on resuming manufacturing operations for automotive, medical technology, and industrial electronics clients without compromising forensic investigation requirements.

Sources
Sources available to members
2 sources