Cyber Incident Victim: SRAM
Date:
Mar 2025
Location:
United States of America
Summary
SRAM said it engaged outside specialists to investigate an IT systems outage that forced the shutdown of its wholesale ordering platform and several other internal systems. The company declined to confirm whether the incident involved a hack or ransomware, noting that it isolated affected areas and restricted access to most of its IT infrastructure as a precaution. After restoring services, it reported that its AXS wireless drivetrain system remained unaffected, while dealer ordering and the RockShox Trailhead suspension app experienced disruptions that have since returned to normal. Outside experts continue to assist in reestablishing secure network access.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In February 2025SRAM experienced an IT systems outage that prompted the company to shut down its wholesale ordering system and other systems. The company hired outside specialists to investigate the cause of the outage. A spokesman for SRAM declined to comment on whether the incident involved a hack or ransomware. As a precaution SRAM shut down the affected areas and closed access to most of its IT systems. On March 27 2025 SRAM informed customers that its systems had been restored.

The spokesman said the incident did not affect SRAM's AXS system which enables riders to customize and gather information from wireless drivetrains and other components. However the outage did impact dealer ordering and the RockShox Trailhead suspension app. Both dealer ordering and the RockShox Trailhead suspension app have since returned to normal operations. The outside experts continue to assist SRAM in restoring secure access to its networks. The article notes that several other bicycle industry brands have faced cyber incidents in recent years. Distributor KHS experienced a two week system outage in 2020 which it attributed to a Russian group. Canyon and Garmin also reported attacks in 2020 and JBI suffered a ransomware attack in 2021.
