CSIDB logo
Incident

TOP-Medien

Incident posture

Attack window
Feb 2025
Location
Switzerland
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:25

Linked entities

Victim
TOP-Medien
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Swiss media company was targeted by a ransomware attack that disrupted its broadcasting and digital operations. Hackers deployed an encryption trojan, temporarily halting productions and live broadcasts of its radio and television services, internet radio, video-on-demand offerings via its app, and content on its news website. The company's mail servers were also affected by the malware. The incident occurred shortly before the initial attack on the organization, which had previously suffered a similar cyberattack months earlier. In response, the company's technical department worked closely with external cybersecurity experts to investigate the breach, contain the damage, and restore the affected systems and data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Top-Medien, the Swiss media company that operates Radio Top and Tele Top, was hit by a second cyberattack in roughly that many months, this time on the evening of 1 February 2025. The company announced the incident on its website "toponline.ch", reporting that hackers had succeeded in deploying an encryption trojan (ransomware) inside its environment. The intrusion was detected around 22:00 local time, after which production and broadcasting operations began to fail. Following the attack, all live programming from Radio Top and Tele Top was temporarily suspended, along with the operator's internet radio streams, video-on-demand offerings served through its "Top now" application, and the web content normally published on "toponline.ch". The company's mail servers were also affected by the trojan, leaving employees and external contacts unable to use email for an indeterminate period.

In the immediate aftermath, Top-Medien stated that it was in close contact with cybersecurity specialists to investigate the incident and clarify the scope of the compromise. The technical department, working alongside external experts, focused on identifying the source of the infection, mapping the extent of the damage, and beginning the process of restoring affected systems and data. Because the incident involved encryption of files and disruption of core publishing and broadcast systems, the operator indicated that recovery would not be instantaneous. Top-Medien did not publish a specific technical timeline for full restoration in the reporting, but it acknowledged that returning the affected programs and platforms to normal operation would require substantial remediation work by both internal IT staff and the third-party specialists engaged for the response. No statements on whether a ransom demand had been received or on the suspected threat actor were included in the company's public communications as relayed in this report.

This February 2025 intrusion was not the first time Top-Medien had been targeted. In May 2024, the same media house was hit by a comparable attack in which an encryption trojan was also deployed. That earlier incident began on the afternoon of 21 May 2024 and produced irregularities and outages across Top-Medien's online, radio, and television services. At that time, the company was unable to broadcast all scheduled programs as planned, and its mail servers were likewise compromised. In comments to "zueriunterland24.ch", Gjusi Brändli, the program director of Radio Top, described the earlier attack as massive and confirmed that Top-Medien was being extorted, indicating that the 2024 event involved a ransom demand from the attackers.

The technical department at Top-Medien worked with external experts during the May 2024 incident as well, focusing on localizing the problems and assessing the full extent of the compromise. Recovery of affected data and programs was expected at that time to take several days. The recurrence of a similar encryption-trojan attack only about eight months later suggests that the operator faced repeated targeting by threat actors employing comparable tactics, specifically ransomware designed to encrypt business-critical files and disrupt broadcast and publishing workflows. In both the May 2024 and February 2025 incidents, the publicly reported impact centered on the same categories of systems: on-air radio and television production, online content delivery, video-on-demand, internet radio, and corporate email.

Sources

Sources available to members: 1 source.

CSIDB