CSIDB logo
Incident

Nah&Frisch Wieser Türnitz

Incident posture

Attack window
Apr 2021
Location
Austria
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Nah&Frisch Wieser Türnitz
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A grocery market experienced a ransomware attack that encrypted all computer files and prompted a ransom demand, forcing temporary closure of the business. The owner confirmed the cyberattack disrupted normal operations and notified customers about the inability to conduct regular business, though specifics of the extortion method were not disclosed. Authorities were informed of the incident, which marked the victim's first encounter with such a cybersecurity event. IT specialists were engaged to restore systems following the encryption of data.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around April 7, 2021, Georg Wieser’s Türnitzer Nah & Frisch market in Austria experienced a ransomware attack that disrupted normal operations. The attack began when all files on the business’s computer systems were suddenly encrypted, rendering them inaccessible. Following the encryption, the attackers delivered a blackmail message demanding payment, though the specific format and content of this message were not disclosed publicly. Market owner Georg Wieser confirmed the incident to local media outlet NÖN, stating the attack forced the temporary closure of the store starting Wednesday, April 7. A physical notice informing customers of the closure due to "cyberattacks and blackmail" was posted at the market premises in the days following the incident. Wieser emphasized his priority was communicating the operational disruption to customers rather than detailing the attackers’ demands. The business had no prior history of similar cybersecurity incidents according to the owner.

Wieser immediately reported the ransomware attack to unspecified authorities following its detection. The market’s IT systems team initiated efforts to restore operations, described as "rectification" work, though technical specifics about containment measures or decryption attempts were not disclosed. No information was provided regarding the duration of the closure, data theft claims by attackers, or whether systems were restored from backups. The incident caused direct operational impacts through forced closure and loss of computer system functionality. Public consequences included customer notifications via physical signage and media statements confirming the attack’s occurrence and business disruption. Wieser did not disclose whether ransom payments were made or negotiated, nor were any threat actor groups or ransomware variants identified in available reporting.

Sources

Sources available to members: 1 source.

CSIDB