CSIDB logo
Incident

Morgenstern AG

Incident posture

Attack window
Aug 2025
Location
Germany
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-17 19:27

Linked entities

Victim
Morgenstern AG
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Aug 2025
Disclosed
Aug 2025
Resolved
Pending

Summary

Morgenstern AG experienced an attempted cyberattack that was reported as stopped, prompting the company to shut down its IT systems and operate in emergency mode. External IT service providers, forensic investigators, the local police and the internal IT team were engaged to examine all systems and restore normal services. Customers were advised to close any TeamViewer connections and update their passwords, while the company noted a temporary use of a Gmail address for contact. The exact entry point of the attack remained undetermined.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Morgenstern AG, headquartered in Reutlingen, is a provider of document and printing solutions that was founded in 1971 and now employs about 300 staff across eleven locations. On Thursday, 7 August 2025 the company experienced an attempted cyberattack that it said it had successfully stopped. The first indication of a problem reached a blog author on Friday, 8 August 2025 through a private Facebook message that described a current disturbance limiting the company’s accessibility. A reader of that message commented that Morgenstern had probably been hacked that day. On Tuesday, 12 August 2025 an anonymous reader directed the author to the latest development, noting that visiting the domain morgenstern.de triggered a popup. The popup stated that the Morgenstern group had stopped an attempted cyberattack on 7 August 2025 and, for security reasons, had shut down its IT systems, placing the company in emergency mode for the coming days. The announcement also said that external IT service providers, forensic specialists, the criminal police in Esslingen and the internal IT team were examining all systems to restore normal service as quickly as possible.

As part of its response, Morgenstern AG asked its customers to close any active TeamViewer sessions and to change their passwords. The company noted that, at certain times, a Gmail address had been used as a contact address for Morgenstern, which raised the possibility that its internal email infrastructure had been affected. The public announcement on 12 August 2025 was also distributed by email to customers, in which the attempted attack of 7 August was described as having been stopped according to the company’s own assessment. Among the customers mentioned in the communication was the textile manufacturer Trigema, which is known nationwide in Germany. In the comment section of the original blog post, readers discussed various security practices, including the use of TeamViewer with easily guessable passwords, the storage of weak passwords in Excel files and the potential compromise of KeePass databases. An anonymous commentator questioned whether there are publicly available statistics on incidents that involve TeamViewer. Another comment referenced a report by Micah Liebergatherer from May 2025 concerning accurate password handling. These remarks illustrate the topics that were being debated in relation to the incident.

The article concludes by noting that Morgenstern AG’s reaction—bringing in external security experts, shutting down systems and informing customers—demonstrates the seriousness with which the company treated the event. It points out that the exact entry point of the attack, whether via TeamViewer or another channel, remained unclear from the information available. The piece observes that cybersecurity is a continuous process that demands constant attention from all involved parties. Finally, the Morgenstern case is presented as an indication that even established providers can be vulnerable to problems such as unsafe software licences or faulty authentication solutions. No further details about the attack’s impact or any data loss are provided in the source material.

Sources

Sources available to members: 1 source.

CSIDB