Simpson Manufacturing took systems offline after October 2023 cyberattack

Organization
Simpson Manufacturing
Exploit
Hacking
Industry
Manufacturing

Simpson Manufacturing Co., the Pleasanton, California parent of Simpson Strong-Tie, disclosed a cyberattack in a Form 8-K filed with the U.S. Securities and Exchange Commission. The company said it identified disruptions to its IT infrastructure and applications on October 10, 2023.

Simpson took certain systems offline as a defensive measure to contain the malicious activity and engaged third-party cyber security specialists to support its investigation and recovery. The company said the work to assess the nature and scope of the incident remained ongoing and was in its early stages.

The filing warned that the incident had already caused disruption to parts of the company's business operations and was expected to continue doing so while remediation ran its course. A second Form 8-K, filed on October 19, 2023, said the incident had caused wide scale disruption of the company's business operations for approximately three days, that the unauthorized activity had been contained, and that although Simpson was unable to predict the full impact it did not expect a material effect on its financial condition.

No ransomware group claimed responsibility and Simpson did not attribute the attack. BleepingComputer and The Register both noted that an abrupt shutdown of systems is consistent with a ransomware infection, but neither could confirm that was the cause. Simpson makes structural connectors, fasteners and truss plates for residential and commercial construction, reported net sales of $2.12 billion in 2022 and employed roughly 5,150 people.

Sources