CSIDB logo
Incident

Läderach AG

Incident posture

Attack window
Sep 2022
Location
Switzerland
Status
Historical
CIA posture
Available to members
Updated
2025-10-17 00:00

Linked entities

Victim
Läderach AG
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Swiss chocolatier experienced a cyber attack disrupting production, logistics, and administrative operations, though retail stores domestically and internationally remained operational with unaffected local sales. The company activated its emergency response protocol upon detection, engaged external IT and forensic specialists, and notified authorities while minimizing internal tool usage as a precaution. Online orders continued with possible delivery delays, and the full scope of the incident remained under investigation during containment efforts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 5, 2022, Swiss chocolatier Läderach AG detected a cyber attack targeting its systems, prompting immediate activation of its pre-established emergency response board. The board was tasked with verifying the incident’s scope and implementing containment measures, with authorities notified without delay. Initial assessments confirmed disruptions primarily impacted production facilities, logistics operations, and administrative functions across the organization. Retail branches in Switzerland and internationally remained operational, with in-store sales unaffected, while online orders continued processing through the company’s webshop, though potential delivery delays were anticipated due to backend system impairments. Internal work tools and communication channels were restricted to essential use only as a precautionary measure to limit further exposure.

The emergency board collaborated with external IT security specialists and forensic investigators to analyze the attack’s origin, methodology, and full operational impact, though no technical specifics regarding attack vectors or actor attribution were disclosed publicly. Business continuity protocols prioritized maintaining retail and e-commerce operations despite persistent disruptions to manufacturing and supply chain management. No customer data breaches or financial system compromises were referenced in initial statements. Recovery efforts focused on restoring affected systems while minimizing operational downtime, with ongoing investigations determining the incident’s root cause and long-term implications for infrastructure resilience. The company’s headquarters in Glarus, Switzerland, coordinated the response across its global workforce of approximately 1,500 employees, maintaining transparency through corporate communications channels led by Global Head Matthias Goldbeck.

Sources

Sources available to members: 1 source.

CSIDB