Thyssenkrupp Automotive Body Solutions
Incident posture
Linked entities
- Victim
- Thyssenkrupp Automotive Body Solutions
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A German industrial engineering and steel production conglomerate disclosed a security breach that impacted its Automotive Body Solutions business unit at a factory in Saarland employing around 1,000 employees. Company spokeswoman Evelin Veit confirmed that IT security personnel recognized the unauthorized access to the IT infrastructure early on and contained the danger, working toward a gradual return to normal operations. The decision to shut down the IT systems suggests the organization was likely the victim of a ransomware attack, though specific details of the attack were not disclosed. The incident is currently reported as under control, with operations being restored incrementally. This marks another cybersecurity incident for the conglomerate, which has previously faced multiple breaches, including ransomware attacks affecting its materials and system engineering divisions in prior years.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Thyssenkrupp, a large German industrial engineering and steel production multinational conglomerate, disclosed a security breach that impacted its Automotive division. The incident specifically targeted Thyssenkrupp Automotive Body Solutions, one of the company's business units, and the attack became public at the beginning of February 2025 when initial reports emerged from the Saarbrücker Zeitung. The company confirmed the cyber attack last week, according to reporting dated February 1, 2025. Company spokeswoman Evelin Veit verified that the attack only affected the Automotive Body Solutions business unit, rather than spreading to other divisions within the broader Thyssenkrupp group. The breach involved unauthorized access to the IT infrastructure of the affected business unit, as confirmed by Thyssenkrupp's official statements to the press.
The attack hit a factory in Saarland that employs around 1,000 employees, making it a significant operational site for the Automotive Body Solutions division. Thyssenkrupp AG has an annual revenue of over $41 billion and employs more than 103,000 personnel globally, making the targeted facility part of a much larger industrial enterprise. In response to detecting the unauthorized access, the company made the decision to shut down its IT systems at the affected location, a precautionary measure typically associated with containing serious security incidents. The decision to take systems offline suggests that Thyssenkrupp Automotive Body Solutions likely became the victim of a ransomware attack, though the company did not disclose specific details about the nature of the intrusion or the attack vector used by the threat actors.
The response to the incident was coordinated between the IT security team of the Automotive Body Solutions business unit and the IT security personnel of the broader Thyssenkrupp Group. Spokeswoman Evelin Veit provided a statement to the technology news website Golem.de explaining the discovery and containment process. According to Veit, "The IT security of Automotive Body Solutions recognized the incident early on and has now contained the danger with the IT security of the Thyssenkrupp Group." The early detection of the intrusion allowed the company to contain the threat before it could spread beyond the Automotive Body Solutions division to other parts of the organization. Veit described the situation as currently being "under control" following the containment actions taken by the combined IT security teams.
Following the containment of the threat, Thyssenkrupp began working on restoring operations at the affected facility. The company indicated it was pursuing a "gradual return to normal operations," suggesting that the recovery process would be implemented in stages rather than as an immediate full restoration. This measured approach to bringing systems back online is consistent with standard incident response practices following a significant cyber attack that required systems to be taken offline. The shutdown of IT systems during the investigation and containment phase would have inevitably affected production and administrative operations at the Saarland factory during that period.
This incident represents one of multiple cyber attacks that have targeted Thyssenkrupp and its various subsidiaries over the years. In 2012, the company was targeted by another cyber attack that was classified as "heavy" and of "exceptional quality," establishing a history of significant security incidents. In 2016, alleged Asian threat actors targeted Thyssenkrupp to steal company secrets, with investigators speculating that the attack was carried out by a group of professional hackers from Southeast Asia interested in the technological know-how and research activities of the company. On December 28, 2020, Thyssenkrupp Materials group of companies based in the United States and Canada were breached by the NetWalker ransomware group, with the hackers managing to access sensitive HR information and documents about the company's current and former employees. The confidential information accessed during that 2020 breach included Social Security Numbers and bank account information of employees. In August 2020, Thyssenkrupp System Engineering was hit by the Mount Locker ransomware group, and in January 2021, a Thyssenkrupp subsidiary was the victim of a ransomware cyberattack that caused the encryption of its servers and employee workstations. In December 2022, Thyssenkrupp AG announced that the Materials Services division and corporate headquarters were hit by a cyberattack.
Sources
Sources available to members: 2 sources.