CSIDB logo
Incident

Nyrstar

Incident posture

Attack window
Jan 2019
Location
Belgium
Status
Historical
CIA posture
Available to members
Updated
2025-11-05 00:00

Linked entities

Victim
Nyrstar
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Belgian metals producer experienced a cyberattack that prompted the shutdown of certain IT systems, including email services, to contain the incident. The company confirmed its metals processing and mining operations remained undamaged by the attack. Recovery efforts involved collaboration with key IT partners and global cybersecurity agencies to implement a technical restoration plan following containment of the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 22, 2019, Belgian metals producer Nyrstar experienced a cyber-attack that disrupted its information technology infrastructure. The company responded by proactively shutting down certain IT systems, including email services, to contain the incident. This action was taken as a precautionary measure to prevent further spread or escalation of the attack within their network environment. Nyrstar confirmed that its core industrial operations—including metals processing facilities and mining activities—remained unaffected by the cybersecurity incident, with no physical damage reported to production assets. The company issued a public statement on the same day acknowledging the attack and outlining initial containment steps. No specifics were provided regarding the attack vector, duration of system compromises, or identity of threat actors.

Nyrstar immediately engaged key IT partners and global cybersecurity agencies to develop a technical recovery plan following containment of the breach. The collaboration aimed to restore affected systems while maintaining operational continuity across its industrial sites. The company did not disclose whether data exfiltration occurred, financial losses were incurred, or customer operations were impacted by the IT shutdown. Throughout the incident response, Nyrstar maintained that production outputs and metallurgical processes continued without interruption, indicating successful isolation of operational technology (OT) networks from compromised IT infrastructure. Recovery efforts focused exclusively on business systems rather than industrial control environments, with no reported extensions to supply chain partners or subsidiary locations.

Sources

Sources available to members: 1 source.

CSIDB