CSIDB logo
Incident

SDZ Druck und Medien GmbH

Incident posture

Attack window
May 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
SDZ Druck und Medien GmbH
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted SDZ Druck und Medien GmbH, disrupting computer and editorial systems, including critical infrastructure for e-paper production, website operations, and email communications. This caused the unavailability of the Tuesday editions of affiliated newspapers and severely limited digital workflows, preventing standard reader and editorial interactions. Technical teams are actively addressing the incident, though the full scope remains unclear, with updates being provided through the organization’s websites and social media channels. The reader service remains accessible via phone despite high call volumes and potential delays.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On the night leading into Tuesday, May 31, 2022, SDZ Druck und Medien GmbH—publisher of the Schwäbische Post and Gmünder Tagespost newspapers—experienced a cyberattack targeting its computer and editorial systems. The intrusion disrupted critical infrastructure responsible for producing the E-Paper editions, rendering the Tuesday issues of both publications unavailable to readers. Internal operations were severely impaired, with editorial teams unable to fully utilize their homepage content management systems or conduct routine email communications. The attack paralyzed the organization’s primary digital channels, isolating staff from external email correspondence and limiting their capacity to publish updates through standard workflows. This systemic failure extended to customer-facing services, compounding operational paralysis across multiple departments.

Technical response teams immediately initiated recovery efforts, working intensively to restore compromised systems, though the full scope of the attack remained undetermined during the initial response phase. The publisher prioritized transparency, directing readers to monitor official websites and Facebook channels for progress reports amid the disruption. Customer service contingencies were activated, with the Leserservice (reader service) phone line remaining operational for urgent inquiries, though high call volumes led to significant wait times. The incident’s logistical repercussions included prolonged production halts for digital editions and constrained editorial output, directly impacting news distribution timelines. Organizational communications emphasized regret for service interruptions while maintaining focus on technical remediation and stakeholder updates through alternative platforms.

Sources

Sources available to members: 1 source.

CSIDB