Manufacturing

Industry

German Napkin Maker Insolvent after Ransomware Attack

May 19, 2025

German paper napkin manufacturer, Fasana, is now facing insolvency after a ransomware attack this past May disrupted all forms of operations at the company.
In a bit of irony, on May 19, Fasana’s entire printing infrastructure suddenly began producing ransom notes. In the attack, it appeared every laptop and desktop PCs ended up locked down. The next day, May 20, the company was unable to process orders worth over €250,000 ($287,467).
For nearly two weeks, Fasana was unable to: Print delivery notes or invoices, fulfill customer orders and process employee salaries.
In that short timeframe, the company suffered financial losses of over €2 million ($2.3 million). Dr. Dirk Wegener, the court-appointed insolvency administrator, said the company could not conduct basic business operations.

read more

Ransomware Attack At BTU International

August 11, 2025

Westford, Massachusetts-based BTU International, a thermal processing equipment provider, suffered a ransomware attack in August affecting its information technology (IT) systems where personal information ended up stolen.
“On or around August 11, 2025, BTU became the victim of a ransomware attack that affected its IT systems,” the company said in a notice to victims of the attack. “Upon discovering this activity, we immediately took protective actions to stop the unauthorized access, notified U.S. federal law enforcement, including the Federal Bureau of Investigation (“FBI”), assessed the security of our network and systems, and launched an investigation with the assistance of leading cybersecurity specialists.”
BTU suffered a ransomware attack in April 2021 from the DarkSide attack group.

read more

First-Aid Product Maker, DC Safety, Hit In Cyberattack

December 11, 2024

First-aid and preparedness product manufacturer, DC Safety Sales Co. suffered a cyberattack late last year and is now informing victims of the attack where personally identifiable information ended up stolen.
On January 21, 2025, Theodore, Alabama-based DC Safety learned an unauthorized third party exploited a Zero Day vulnerability in a third-party application operating on a limited number of DC Safety’s servers.
Upon discovery of the December 11, 2024 attack, the company isolated the servers, contained the impact, and conducted an investigation, which included working with third-party specialists, to determine the nature and scope of the event.

read more

Second Attack In 2 Months For VF Outdoor

April 23, 2025

For the second time over a two-month period, Denver, Colorado-based VF Outdoor LLC, suffered a credential stuffing attack against one of its brands, this time The North Face.
“On April 23, 2025, we discovered unusual activity involving our website, thenorthface.com, which we investigated immediately,” the company said in a letter to victims. “Following a careful and prompt investigation, we concluded that an attacker had launched a small-scale credential stuffing attack against our website on April 23, 2025.”
A credential stuffing attack is a specific type of cybersecurity attack where the threat actor uses account authentication credentials stolen from another source, such as a breach of another company or website, to gain unauthorized access to user accounts.

read more

Cyberattack at Watch Maker, Nixon

December 18, 2024

Watch maker, Nixon, Inc. suffered a cyberattack that made off with personally identifiable information of various victims.
“On December 18, 2024, we were alerted to unusual activity involving our information technology environment,” the company said in a letter to victims. “In response, we initiated an investigation, took steps to secure our systems, and notified law enforcement.” Additionally, the company hired a third-party forensic firm to assist in the investigation.
“On April 18, 2025, our investigation determined an unauthorized individual accessed files on our systems containing your information,” the company said.

read more

Cyberattack Hits KWS Manufacturing

January 24, 2025

Burleson, Texas-based KWS Manufacturing Company, LLC suffered a cyberattack where threat actors made off with personally identifiable information.
“We recently learned of suspicious activity in our computer environment,” the company said in a notice to victims of the incident. “We immediately launched an investigation, with the assistance of outside experts. The investigation determined that an unauthorized third party accessed our computer systems during the period of January 24-25, 2025, and obtained some company files. We conducted a diligent review of the affected files to determine what personal information they contained.”
KWS officials said in the letter there is no indication the stolen personal information ended up misused as a result of this incident, The investigation did determine the affected company files contained your name and an additional amount of information the company redacted from the letter to victims.

read more

Cyberattack at Security Provider, CPI

September 12, 2024

Security product maker, Chatsworth Products, Inc. (CPI), fell victim to a cyberattack last September and after an investigation is now informing victims of the incident.
“CPI recently became aware of suspicious activity within their computer network,” the company said in a notice to victims. “Upon learning of the suspicious activity, CPI immediately took steps to secure their systems and launched an investigation into the nature and scope of the activity with the assistance of third-party cybersecurity and data privacy specialists.
“The investigation determined that an unauthorized actor accessed the CPI network at various times between September 12, 2024 and September 23, 2024, and certain information contained within those systems ended up viewed or copied by the unauthorized actor during that time,” the company said.

read more

Mission Bell, a CA Millwork Maker, Hit In Cyberattack

January 31, 2025

Morgan Hill, CA-based Mission Bell, an architectural millwork and casework manufacturer, suffered a data security incident that may have involved personally identifiable information.
Moreover, the Mission Bell data breach involved sensitive personal information belonging to an undetermined number of individuals.
“On February 1st, we discovered a security breach that occurred on January 31st. After conducting a lengthy investigation, we determined that unauthorized access to certain personal information may have taken place,” the company said in a letter to victims.

read more

VF Outdoor, Parent to Timberland, North Face, Suffers Credential Stuffing Attack

March 13, 2025

VF Outdoor, the parent company to The North Face and Timberland, suffered a credential stuffing cyberattack last month and decided to release details of the attack even though the firm said the threat actors did not obtain any customer data from the site.
On March 13, the company ended up alerted to unusual activity involving its website, [thenorthface.com or timberland.com], that prompted it to investigate immediately.
“Following a careful investigation, we concluded that an attacker had launched a small-scale credential stuffing attack against our Website on March 13, 2025,” the company said in a letter to victims. “A ‘credential stuffing attack’ is a specific type of cybersecurity where the attacker uses account authentication credentials (e.g., email addresses/usernames and passwords) stolen from another source, such as a breach of another company or website, to gain unauthorized access to user accounts.

read more

McIntosh Laboratory, Audio Product Maker, Hit in Cyberattack

October 17, 2025

High-end audio equipment maker, McIntosh Laboratory, Inc. suffered a cyberattack in October which disrupted access to various systems within the network.
“On October 21, 2025, McIntosh detected suspicious activity and experienced a disruption of access to certain of our digital systems,” the company said in a notice to victims. “In response, we took immediate steps to secure our network and engaged forensic experts to investigate.”
Based on the investigation, McIntosh found the attacker accessed and acquired certain data between October 17 and 19.

read more