Ransomware incident at Oettinger brewery

The Oettinger brewery has been the victim of a cyber attack. The perpetrators apparently encrypted and copied data.

listen Print view
Highly distorted image of a finger on a keyboard, with a digital exclamation mark in the foreground

(Image: janews/Shutterstock.com)

2 min. read

Cyber criminals have attacked the Oettinger brewery. They have apparently encrypted and copied data in order to blackmail the company.

Detailed website on the Darknet about the Oettinger break-in at the RansomHouse cyber gang.

(Image: Screenshot / dmk)

An entry about the Oettinger brewery has appeared on the darknet website of the criminal online gang RansomHouse, in which the perpetrators claim to have penetrated the IT systems on April 19. According to the entry, they encrypted the company's data. As evidence, they uploaded a directory structure and documents. These included sensitive information, with one directory indicating warnings for employees.

A list of the copied data apparently contains warnings for employees.

(Image: Screenshot / dmk)

Overlying directories dated April 20, 2025, for example, refer to shipping and logistics, the individual company locations, the vehicle fleet, warehouse management, quality management systems and more.

In response to our inquiry, the Oettinger brewery commented on the IT incident as follows: "We are currently investigating the cyber attack on Oettinger Getränke together with IT forensic experts, the data protection authority and cybercrime specialists. The same applies to the issue of data leaks. For tactical investigative reasons, we are unable to comment further at this time. Production and logistics are not affected by the cyberattack."

Videos by heise

The company thus confirms the intrusion into its corporate IT. While the supply of beer and drinks has been secured, communication, for example via email, was apparently temporarily disrupted.

Please also read:

Topic page on ransomware on heise online

Attacks on IT by criminal gangs, in particular with the extraction of data and encryption using ransomware (also known as "double extortion") after successful break-ins, remain commonplace. However, it now mostly affects smaller medium-sized companies, which is why there are fewer reports about it in the media. This could be one of the reasons why ransom payments following such ransomware attacks fell significantly in 2024, as the company Chainalysis found out in a study.

(dmk)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.