SEMCO Technologies
Incident posture
Linked entities
- Victim
- SEMCO Technologies
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A Montpellier-based semiconductor startup, Semco Technologies, was targeted by Russian-affiliated hackers who claimed responsibility for the cyberattack while the company was pursuing an initial public offering on Euronext. The attackers stole personal data belonging to employees, including passport scans and invoices, and subsequently leaked files on a darknet site. The company confirmed the breach, stating it had implemented all necessary measures to contain the impact and that the attack did not disrupt its equipment or overall operations. Despite the incident remaining undisclosed publicly during the process, Semco Technologies successfully completed its IPO, raising €45 million with investor demand exceeding the offering by 5.6 times, with trading set to begin shortly after the disclosure.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On July 7, 2025, it was publicly reported that Semco Technologies, a French semiconductor startup based in Montpellier, had been hit by a cyberattack carried out by hackers described in press coverage as Russian. The incident came to light as the company was in the final stages of its initial public offering on Euronext. According to the report, the attackers claimed responsibility for the intrusion and subsequently stole a range of personal data belonging to company employees. Among the data exfiltrated were passports and invoices, indicating that the breach specifically targeted human resources and financial documentation rather than, or in addition to, production-related technical assets. After the theft, the attackers published some of the stolen files on a darknet site, which was accessible to journalists who confirmed the leak's authenticity by reviewing the posted material.
The timing of the attack was particularly notable because it overlapped with a major corporate milestone for Semco Technologies. The company was conducting its IPO on Euronext Growth at the moment the intrusion was discovered and disclosed. Despite the security incident, the company confirmed that it had taken all necessary measures to contain the impact as soon as the attack was detected. Semco Technologies stated that the cyberattack did not disrupt the operation of its equipment or the broader functioning of the company. The statement, attributed to the company by La Tribune, emphasized that business operations and production capabilities were unaffected by the intrusion, which appears to have been limited in its technical impact on operational technology even though sensitive employee data was compromised.
The financial trajectory of the company was not derailed by the breach. On July 4, 2025, Semco Technologies announced that it had successfully raised a total of 45 million euros through its IPO. Investor demand was strong, with subscriptions reported to be 5.6 times the number of shares offered, indicating robust market confidence. Negotiations on Euronext Growth were scheduled to begin on Wednesday, July 9, 2025, just days after the attack became public knowledge. The fact that the blackmail attempt stayed largely confidential until the press report meant that the cybersecurity incident did not visibly disrupt the capital-raising process or the public market debut of the firm.
In terms of response, Semco Technologies activated its incident handling procedures immediately upon detection, characterizing its actions as putting in place all necessary measures to circumscribe the impact of the attack. The company publicly confirmed the incident when contacted by the press, demonstrating a degree of transparency with media, though it framed its response around the reassurance that operations remained intact. The attackers' use of a darknet leak site to publish stolen employee data suggests a double-extortion tactic typical of ransomware-adjacent threat actors, in which victims are pressured not only by the encryption or disruption of systems but also by the threat of public exposure of sensitive information. The personal nature of the stolen records, including identity documents such as passports, raises the prospect of identity theft or fraud risks for affected employees, even though the company did not, in the available reporting, detail specific remediation steps offered to staff whose data was exposed.
The available reporting does not specify the exact date the intrusion occurred, the vector of initial compromise, the duration of the attackers' presence in the network, or the precise technical means by which data was exfiltrated. Similarly, the source article does not identify the threat actor group by name, referring only to "hackers russes," nor does it state whether a ransom demand was issued, what the company's position was on any such demand, or whether any payment was contemplated or made. The number of employees affected and the full inventory of data types compromised are also not enumerated beyond the mention of passports and invoices. Law enforcement involvement, regulatory notification under frameworks such as the GDPR, and any third-party forensic or cybersecurity firm engagement are likewise not addressed in the available source material.
The broader context of the incident underscores the increasing intersection of cybersecurity events with corporate finance activities, as Semco Technologies experienced a major data breach at the very moment it was opening itself to public market investment. Despite this, the company's stated position is that its operational continuity was preserved and its IPO succeeded, raising the full 45 million euros on the strength of investor demand that exceeded the offering multiple times over.
Sources
Sources available to members: 1 source.