CSIDB logo
Incident

Eckert & Ziegler SE

Incident posture

Attack window
Feb 2025
Location
Germany
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 17:37

Linked entities

Victim
Eckert & Ziegler SE
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Eckert & Ziegler SE suffered a cyber attack affecting parts of its IT systems, prompting the company to proactively shut down and disconnect the affected systems from the internet to limit potential damage. A task force was immediately assembled and is collaborating with external cyber security and data forensic specialists to investigate the incident and restore normal operations in line with pre-established emergency protocols. While IT systems and the scope of the attack remain under examination, with particular attention to ensuring data integrity, production activities have been largely unaffected and the Executive Board does not currently anticipate any significant adverse effects on the business.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On 13 February 2025, Eckert & Ziegler SE, a company listed on the TecDAX under ISIN DE0005659700 and headquartered at Robert-Rössle-Str. 10, 13125 Berlin, disclosed that it had suffered a cyber attack affecting parts of its IT systems. The company announced the incident through a press release distributed via EQS Distribution Services, a channel that the firm uses for regulatory announcements, financial news, and corporate press releases. The attack prompted immediate precautionary measures, with personnel proactively shutting down the affected systems and disconnecting them from the internet in an effort to minimise any potential impact. From the outset, the company emphasised that the utmost care was being taken to ensure data integrity while technical specialists examined the affected systems and assessed the consequences of the intrusion.

Following the discovery of the attack, Eckert & Ziegler activated its pre-existing emergency plan for such situations. A dedicated task force was assembled immediately and began working in coordination with external cyber security experts and data forensic specialists. The combined internal and external response team was tasked with two parallel objectives: to restore normal operations as quickly as possible and to conduct a thorough analysis of the incident. By the date of the press release, the company stated that its IT systems and the broader effects of the attack were still under examination, indicating that the forensic and investigative phase was actively underway rather than concluded.

In its public communication, the Executive Board of Eckert & Ziegler SE provided an initial assessment of the operational impact of the incident. The company reported that its production operations were largely unaffected by the cyber attack, and the Executive Board expressed the view that it did not currently expect any significant adverse effects on the business. This statement was issued at a stage when full forensic analysis was still in progress, and it reflected the information available to management at that time. The press release did not specify the nature of the attack, the type of threat actor involved, the particular systems compromised, or whether any data had been accessed or exfiltrated, as these details were subject to the ongoing investigation being conducted by the task force and the external specialists.

The incident was reported through the company's official investor relations contact, Karolin Riehle, with communication channels including telephone numbers +49 30 94 10 84-138 and +49 174 1785889, as well as the email address [email protected] and the corporate website www.ezag.com. The press release was timestamped 13 February 2025 CET/CEST, and an archival copy was indicated to be available at www.eqs-news.com. The company's proactive decision to disconnect affected systems from the internet and to engage external cyber security and data forensic experts represented the primary technical and organisational response actions documented in the source material. Beyond the immediate containment measures, the establishment of the task force, the invocation of the emergency plan, and the commitment to data integrity assurance constituted the confirmed scope of the response as described in the company's own public disclosure.

Sources

Sources available to members: 1 source.

CSIDB