Cyber Incident Victim: Vossko
Date:
Nov 2024
Location:
Germany
Summary
A ransomware attack targeted a German food processing company, encrypting internal systems and databases, which disrupted operational processes. The organization restored affected systems and production with assistance from internal IT, external specialists, and law enforcement investigators. Management prioritized operational recovery and implemented continuous security testing alongside infrastructure enhancements to prevent future incidents. Production and initial deliveries have resumed, with ongoing efforts to ensure system integrity while maintaining supply chain commitments to major retail partners.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On November 14, 2024, VOSSKO, a major German poultry and convenience food producer, experienced a targeted ransomware attack that encrypted its internal systems and databases. The encryption of critical infrastructure disrupted operational processes across the organization, impacting production and business continuity. The attack necessitated immediate intervention from VOSSKO’s internal IT department, which collaborated with external cybersecurity specialists to assess the damage and initiate recovery procedures. Law enforcement agencies, including the police and the State Criminal Police Office, were engaged within the first days of the incident, with their IT forensic teams assisting in the investigation of the attack’s origin and methodology. VOSSKO’s management prioritized restoring a secure operational environment and resuming production capabilities as swiftly as possible, emphasizing minimal disruption to their supply chain partners and retail clients, which included major German supermarkets such as Rewe, Aldi, Lidl, and Edeka.

Recovery efforts focused on systematically restoring encrypted systems while implementing enhanced monitoring protocols to ensure security during the transition. By November 22, 2024, VOSSKO confirmed the successful restoration of affected systems and the partial resumption of production and deliveries, though full operational capacity was still being incrementally achieved. Continuous testing and monitoring of all internal systems were conducted to verify stability and security post-recovery. Concurrently, the company committed to long-term investments in IT infrastructure hardening to mitigate future cyber threats. Management publicly acknowledged the collaborative efforts of employees, external experts, and law enforcement, while expressing gratitude to customers and partners for their patience during the disruption. No data theft or secondary impacts beyond operational downtime were disclosed in available reports.
