Ransomware at Nordic distributor Skanlog empties Systembolaget shelves
- Organization
- Skanlog
- Exploit
- Ransomware
- Industry
- Logistics
A ransomware attack on Skanlog, a logistics operator that handles distribution for Sweden's state alcohol monopoly, disrupted deliveries nationwide in late April 2024. Skanlog detected the intrusion on 22 April and shut down its systems, halting shipments to Systembolaget, the government-owned chain that holds exclusive rights to sell beverages above 3.5% alcohol by volume.
Systembolaget said Skanlog handled roughly 15% of its sales volume, weighted toward wine and spirits. A press officer told reporters that certain beers, wines and spirits, and even paper carrier bags, could sell out within days across the chain's stores, though the retailer said there was no risk of running dry entirely. Systembolaget activated backup distribution arrangements with other suppliers.
Skanlog chief executive Mona Zuko said the attackers were a group based in North Korea. The Record reported that the basis for that attribution was not made clear, and it was not corroborated by Swedish authorities in the coverage at the time. The company said its central business system, a Microsoft financial system and an inventory platform called Dynaman were all knocked out.
Skanlog gave no estimate for when its environment would return, saying only that the systems would stay down until they could be repaired and restored. As of the end of April the company had not said publicly whether any data was stolen or whether a ransom demand had been made.