Ransomware attack forced German control systems vendor PSI Software offline
- Organization
- PSI Software SE
- Exploit
- Ransomware
- Industry
- Industrial Software
PSI Software, a Berlin-based vendor whose control and management systems are used by European energy suppliers, pipeline operators and logistics firms, took its systems offline in February 2024 after a cyberattack that it later confirmed involved ransomware.
The company said unusual activity was detected on its network on February 15, 2024. It shut down its mail system overnight so that no messages were sent from PSI systems, and disconnected all external connections as a precaution. That left its website and email unavailable and the business operating at significantly reduced capacity. PSI initially described the incident only as a cyberattack and confirmed several days later that ransomware was involved.
PSI said it was still analysing how the attackers got in. It reported no indication that PSI systems installed at customer sites had been compromised, and no evidence that the attackers reached the remote connections used to maintain customer systems. German authorities were notified and outside security specialists were engaged to help with the investigation and recovery.
As of late February 2024 the company had not restored its internal IT infrastructure, and no ransomware group had publicly claimed responsibility for the attack.