Menu
Browse

Cyber Incident Victim: Sage Software

Date:

Oct 2020

Location:

Germany

Summary

A ransomware attack by the Clop gang targeted a major German enterprise software provider, encrypting internal files and demanding over $20 million. After failed negotiations, the attackers leaked stolen data including employee passports, identification documents, emails, and financial records. The company initially stated customer systems remained unaffected and denied customer data compromise but later confirmed evidence of data theft. Internal network disruptions persisted throughout the week, with operational impacts acknowledged though cloud services reportedly remained functional. The incident affected an organization serving over 10,000 enterprise clients globally with infrastructure software solutions, marking one of the largest known ransom demands at the time.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On October 3, 2020, the Clop ransomware gang breached the internal network of Software AG, a major German technology firm. The attackers encrypted company files and demanded over $20 million in exchange for a decryption key, marking one of the largest known ransom demands in ransomware history. Software AG disclosed the incident on October 5, confirming disruptions to its internal network from a malware attack but asserting that customer-facing cloud services remained operational. The company initially stated it found no evidence of customer data compromise. Two days later, Software AG revised its position in a follow-up press release, acknowledging evidence of data theft. The company maintained a public notice about the attack on its website homepage throughout the week but did not respond to subsequent media inquiries for additional details.

Cyber Incident Image

After ransom negotiations collapsed, the Clop gang escalated their attack by publishing stolen data on their dark web leak site on October 9. Leaked materials included screenshots of employee passports, identification documents, internal emails, financial records, and directory structures from Software AG’s network. Security researcher MalwareHunterTeam identified a copy of the ransomware binary used in the attack earlier that week. The breach impacted Software AG’s internal operations, though the company reiterated that customer services were unaffected. With over 10,000 enterprise clients—including major corporations like Airbus, DHL, and Vodafone—the incident exposed sensitive employee information and corporate data but did not directly compromise customer systems according to official statements. Software AG’s product portfolio, encompassing database systems, enterprise service bus frameworks, and business process management tools, remained operational for external users throughout the incident.

Sources
Sources available to members
1 source