CSIDB logo
Incident

Siloking

Incident posture

Attack window
Jun 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-06-18 22:29

Linked entities

Victim
Siloking
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Siloking, an international manufacturer of feed mixing technology, suffered a ransomware attack that encrypted its IT systems. As a result, the company shifted production to emergency mode while experts analyzed the intrusion and advised on mitigation. The incident highlights the growing threat of ransomware targeting industrial operations and underscores the need for robust cybersecurity defenses. An IT expert from the University of Passau explained the methodology used by the attackers and offered guidance to other companies.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 15 2025, the international feed‑mixing technology manufacturer Siloking, located in Tittmoning within the district of Traunstein, became the target of a cyber‑criminal operation. According to the company’s press release, attackers gained access to Siloking’s IT systems and introduced ransomware that subsequently encrypted those systems. The encryption rendered the normal IT infrastructure unavailable, forcing the company to halt its standard production processes. The incident was reported by the local news outlet PNP.de on the same day, confirming the date and nature of the attack. Siloking described the event as a ransomware incident that compromised its operational technology environment.

In response to the encryption, Siloking shifted its production to an emergency mode to maintain limited output while the IT systems remained affected. The company communicated the situation publicly through a press statement, detailing that the attack had led to the encryption of its systems. An IT expert from the University of Passau was cited in the article as explaining the methodology employed by the attackers in such ransomware events. No further specifics regarding attacker identity, ransom demands, or recovery timelines were provided in the source material. The emergency production mode represents the immediate containment measure enacted by Siloking following the incident.

Sources

Sources available to members: 1 source.

CSIDB