Forgot your password?
typodupeerror
Businesses

German Firm Files For Insolvency After Cybercriminals Shut Down Production For 6 Weeks (theregister.com) 36

German textile firm ZEGO has filed for insolvency and is blaming a March cyberattack that shut down production for nearly six weeks. "ZEGO's filing adds another name to the short but growing list of companies that say a digital break-in was commercially fatal to their business," reports The Register. From the report: In a notice to customers and suppliers, the organization said it had exhausted every available option before seeking insolvency protection. Managing director Johannes Zenglein described the filing as "one of the most difficult steps in our company's 37-year history." "The cyberattack of March 29, 2026, however, impacted our company to an extent that we could not fully compensate for despite our best efforts," Zenglein wrote. "The consequences resulted in a production outage of nearly six weeks and significant financial strain. These effects ultimately impacted our financial situation so severely that filing for insolvency became necessary."

ZEGO did not disclose what kind of attack it suffered, whether ransomware was involved, who was behind it, or whether customer or employee data was compromised. What it has made clear is that the operational disruption alone was enough to push the business beyond the point of recovery. ZEGO said insolvency proceedings have now been initiated, but insisted the filing does not necessarily spell the end of the business. It said it plans to keep production running while administrators attempt to restructure the business, preserve jobs, and keep customers and suppliers on board.

This discussion has been archived. No new comments can be posted.

German Firm Files For Insolvency After Cybercriminals Shut Down Production For 6 Weeks

Comments Filter:
  • by ebunga ( 95613 ) on Monday July 13, 2026 @05:28PM (#66236972)

    If you've dealt with an incident, then you'll know the biggest impediment to recovery is the cyber insurance company forced on you. As soon as you declare an incident, your computers belong to them.

    • If you've dealt with an incident, then you'll know the biggest impediment to recovery is the cyber insurance company forced on you. As soon as you declare an incident, your computers belong to them.

      Personally I'd say the biggest impediment is not replacing the computers than are now forensic evidence. Is their some reason they could not get new systems to replaced the affected systems, to restore backups too?

      • by rsilvergun ( 571051 ) on Monday July 13, 2026 @05:52PM (#66237006)
        The article talked about the cost of customer confidence lost too. In other words even if they came back online the 6-week pause would have caused them to lose a bunch of customers. And they don't have the capital to get them back through advertising campaigns and discounts and such.

        It's actually terrifying how many businesses run at the absolute edge of margins and are perpetually on the verge of collapse. Like how any given city is 3 days away from chaos...

        We focus on the tech companies that are making so much money that they literally cannot spend it fast enough. And that also like to keep a ton of cash around for stock BuyBacks. But it really doesn't take much for most companies to start cutting staff and even shutting all the way down.

        This is both how and why increasing interest rates "fights" inflation. Businesses lose access to credit because it costs more to loan so any little problem in their business immediately becomes a major disaster because of credit crunch and they go under putting a whole bunch of people out of work. Those out of work people spend less reducing demand which slows inflation. If the business doesn't collapse outright it's at least going to do layoffs and pay cuts which achieves the same goal.
        • The people who used to work there will work for whatever company purchases their production facilities or other infrastructure. Unless there's any overall decrease in market demand for what this company produced, others cannot magically increase their own production to satisfy it. Instead they can buy the existing manufacturing capacity and hire the labor who knows how to operate it. Some positions may become redundant, but the ones directly tied to making the products won't.

          It's also funny how you grumb
      • by znrt ( 2424692 ) on Monday July 13, 2026 @06:00PM (#66237010)

        if a 37 year old company can't survive 6 weeks of shutdown and not even get credit to weather the storm and get back on their feet without defaulting on obligations it suggests to me they were already operating on fumes and the cyberattack and aftermath were just the final blow ... and ofc a very convenient explanation for that default.

        • Couldn't start a flood.

          Starting a fire with petrol is too expensive, especially in Germany.

          Downloading your own virus and nuking the IT infrustructure! Yup, that'll do it.

          • by znrt ( 2424692 )

            Starting a fire with petrol is too expensive, especially in Germany.

            and there goes my morning tea! well done ...

        • by AmiMoJo ( 196126 ) on Tuesday July 14, 2026 @05:22AM (#66237628) Homepage Journal

          6 weeks of shutdown for a manufacturing company is not something that is easily survivable. Customers will be looking for alternative suppliers, and many won't switch back. Contracts may have delay and non-fulfilment clauses. Few places are going to have 6 weeks of stock to cover such an event.

          What seems unforgivable is that it took 6 weeks to fix.

          • This wasn't such a big deal before everything had to be "JIT" with near zero inventory because you needed to reduce "days of supply" and improve your "working capital turns" because the consultants told you so.

            On the other hand, six weeks is a very long time, though.

            In a previous job, I had a customer that was hit by a ransomware attack. Once it was discovered they literally told everyone to unplug everything from the network and operate that way. Their ERP software was down so they couldn't even do basic a

            • by AmiMoJo ( 196126 )

              To be honest I'm not sure there is a really good solution to this. It's very difficult to implement a backup system where you can rebuild a corporate network and devices quickly and without significant data loss. Getting as close as possible is expensive too.

            • The problem is that most customers now require custom materials so there's no inventory to be had because it can't be shared between customers.
          • by znrt ( 2424692 )

            i guess it depends on the company and the business. after 3+ decades you likely have built solid relations and have value to offer. ofc customers will be looking for alternatives for the duration but maybe you can even help with that, you can negotiate and offer special conditions thereafter and it being a one-off (shit happens) many custormers might indeed come back. if not, if you do provide value you can rebuild your base. actually they do say they wish to go forward, but a problem seems to be liquidity.

        • Iâ(TM)m aware of long-lived companies who got advised to: sell off then lease back their real estate, reduce cash on hand myriad ways, changing buying habits (so inventory value on the books plunges), etc. Literally, theyâ(TM)ve been coached to eliminate every bit of those decades of reserves.

          When a bad thing happens, the company dies.

    • by N1AK ( 864906 )
      Are there really Cyber-Insurance vendors people are picking that don't include considerable cover for disruption? I've met with two IT leadership teams who've been through major incidents with two different insurance vendors where they had faced significant disruption; in both cases the insurer helped them source and deploy alternative infrastructure/services and were willing to spend a considerable amount to minimise the impact of the incident. The assumption is that this was motivated by the fact the insu
  • by Gravis Zero ( 934156 ) on Monday July 13, 2026 @06:06PM (#66237020)

    "The consequences resulted in a production outage of nearly six weeks and significant financial strain. These effects ultimately impacted our financial situation so severely that filing for insolvency became necessary."

    That's a funny way of explaining that they neglected to implement proper security measures and backup measures for decades.

    This is ultimately what wishful thinking and downplaying the importance of cybersecurity gets you.

    • That's a funny way of explaining that they neglected to implement proper security measures and backup measures for decades.

      The security measures I can forgive. Or, rather, I can extend them the benefit of the doubt. There are so many vectors and ins, I'm willing to issue a mulligan on that.

      But the backup... what is the difference between a ransomware attack and a hard drive failure? Only the predicate intent. The result is identical.

      So while I have room for tolerance for a security failure, I have no to

      • That's a funny way of explaining that they neglected to implement proper security measures and backup measures for decades.

        The security measures I can forgive. Or, rather, I can extend them the benefit of the doubt. There are so many vectors and ins, I'm willing to issue a mulligan on that.

        But the backup... what is the difference between a ransomware attack and a hard drive failure? Only the predicate intent. The result is identical.

        So while I have room for tolerance for a security failure, I have no tolerance for the aftermath. Anyone can get hit by it, but being harmed by it for more than a day, that's on them. Anything more than a day's down time to re-image every hard drive and firmware back to known good, is just simply incompetence.

        Not having a disaster recovery plan, which would include backups, restore procedures, etc, is a security failure. As was already mentioned, you cannot rely on rebuilding the same machines in the event of a security incident. Those machines will be required for forensics, sometimes whether you have insurance or not, for example if personal data is involved.

        • That's a funny way of explaining that they neglected to implement proper security measures and backup measures for decades.

          The security measures I can forgive. Or, rather, I can extend them the benefit of the doubt. There are so many vectors and ins, I'm willing to issue a mulligan on that.

          But the backup... what is the difference between a ransomware attack and a hard drive failure? Only the predicate intent. The result is identical.

          So while I have room for tolerance for a security failure, I have no tolerance for the aftermath. Anyone can get hit by it, but being harmed by it for more than a day, that's on them. Anything more than a day's down time to re-image every hard drive and firmware back to known good, is just simply incompetence.

          Not having a disaster recovery plan, which would include backups, restore procedures, etc, is a security failure. As was already mentioned, you cannot rely on rebuilding the same machines in the event of a security incident. Those machines will be required for forensics, sometimes whether you have insurance or not, for example if personal data is involved.

          Has the EU tried fining the threat actors?

      • by AmiMoJo ( 196126 )

        Eh, HDD failure and ransomware are not the same things. If you have two HDDs in a mirror configuration, and one of them dies, you lose nothing. If you get ransomware, both are encrypted.

        If one machine suffers an SSD failure, you lose one machine and inconvenience one user. If your network is hit with ransomware, potentially it spreads to every machine and through file servers, affects all users.

        Obviously you should have a 321 backup system, but management tends to resist anything too robust. And even with t

  • Assuming (yes!) that the statement is truthful, it is yet another case of a business that failed to recognise the importance of information systems' security and have not survived (at least, in its present form). The generation of businesses that rely on IT and fail to protect their IT (proactive measures, mitigation of attacks, contingency plans, etc.) will inevitably die off.
    • by HiThere ( 15173 )

      And the main one should be "Never expose your critical information on the internet, or to any computer connected to the internet.".

      That's not sufficient, but it would eliminate most problems.

      • And the main one should be "Never expose your critical information on the internet, or to any computer connected to the internet.".

        That's not sufficient, but it would eliminate most problems.

        One good practice. In addition, remove internet in off hours.

  • A bit short on technical details.
  • I'm surprised a textile firm would be that exposed to such things. Makes me think the company is trying to get out of some obligation, but I don't know much about German corporate law to speculate.

  • Maybe this will be a lesson to manufacturing as a whole that putting industrial control logic into the cloud has always been a retarded idea. Even if you have perfect security, your competition can still shut down your production by hiring a DDoS.

  • Nobody is immune (Score:5, Interesting)

    by serafean ( 4896143 ) on Tuesday July 14, 2026 @04:47AM (#66237608)

    Nobody is immune, survival is about planning, and a bit of luck :
    In 2017 Maersk almost got destroyed: notPetya wiped their systems, including domain controllers. Luckily a power outage in ghana kicked the local DC offline during the attack, and thus the sole remaining copy was perserved. Talk about luck.

    https://www.wired.com/story/no... [wired.com]

    • Nobody is immune, survival is about planning, and a bit of luck

      It is very true that best practices will not guarantee successfully keeping the bad guys out. But we hear so many stories about the keys to the pwned kingdom being accidentally left in plain view. A lot of low hanging fruit out there.

      Of course, having the IT department as a cost center doesn't help either.

  • I'm not sure that the cyber attack here killed the company or simply put it out of its misery. It didn't sound like it was in a healthy operating state.

    • I'm not sure that the cyber attack here killed the company or simply put it out of its misery. It didn't sound like it was in a healthy operating state.

      I agree, sounds like they were short on money, and decided to take an axe to the IT department. Then the inevitable happened.

  • ... that they shut down is that they had their entire IT connected to the 'Net, with no air gaps, and no valid backups.

  • The biggest risk is connecting a textile mill to the internet. You have to air gap your textile machines from your computers.

  • Police in this country are poorly designed. They work for the Mayor, and he works for the largest campaign contributions (money is #1 factor in determining elections, from what I've read). So, they work for the wealthiest locals and corporations. The ideal of "protect and serve" only came out because of abuses and has never really been true. Police will tell you that. Of course, internal auditing/oversight (internal affairs) is never the best idea. (Boeing 737 is a great (or horrid) example, depending on ho

You can be replaced by this computer.

Working...