CSIDB logo
Incident

Zur Rose Group AG

Incident posture

Attack window
Jan 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-22 00:00

Linked entities

Victim
Zur Rose Group AG
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The provided article does not contain verifiable details about a cybersecurity incident involving Zur Rose Group AG. The content primarily consists of corporate website navigation elements, a generic 404 error message stating the page is "on medical leave," and a headline referencing achieved revenue targets without any mention of security breaches, disruptions, or unauthorized access. No technical or operational impacts related to a cyber incident are described in the available material.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 18, 2022, Zur Rose Group AG experienced a disruption affecting public access to sections of its corporate website. The incident manifested as a 404 error page replacing expected content under the "Corporate" and "Newsroom" sections of the DocMorris AG domain. Visitors attempting to access specific pages, including a news article titled "Zur Rose Group: Revenue and earnings targets for 2022 achieved; significant step towards profitability," encountered a customized error message stating "This page is on medical leave. Sorry about that. We are attending to it with due care." This message utilized medical terminology consistent with the company's healthcare branding. The disruption occurred on a page dated January 18, 2022, though the error message appeared under a URL timestamped January 19, 2022, at 17:45:02, suggesting ongoing technical issues spanning at least two calendar days.

The organization publicly acknowledged the service interruption through the error message, confirming awareness of the problem and active remediation efforts. The statement "We are attending to it with due care" indicated operational response activities were underway, though no technical details regarding root cause, attack vectors, or data impact were disclosed. The affected page contained financial performance information, potentially limiting investor access to time-sensitive corporate announcements during the outage window. No secondary statements regarding system restoration timelines, forensic findings, or regulatory notifications appeared in the available source material. The incident documentation remained limited to this single error message without subsequent public updates on resolution status or broader operational consequences.

Sources

Sources available to members: 1 source.

CSIDB