Tempur Sealy shut down IT systems after July 2023 cyberattack

Organization
Tempur Sealy International
Exploit
Hacking
Industry
Manufacturing

Tempur Sealy International, the Kentucky based maker of Tempur-Pedic, Sealy, Cocoon and Stearns & Foster bedding, identified a cyberattack on its network on July 23, 2023.

The company disclosed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission on July 31. Chief financial officer Bhaskar Rao wrote that Tempur Sealy had proactively shut down certain of the company's IT systems, resulting in a temporary interruption of operations. The filing did not quantify the disruption or say whether data had been taken.

Tempur Sealy said it activated its incident response and business continuity plans, engaged outside legal counsel and a cybersecurity forensics firm, and notified law enforcement. By the time of the filing it had begun bringing critical systems back online and had resumed operations.

The company did not describe the nature of the attack. SecurityWeek noted that being forced to take systems offline suggested ransomware might have been involved. Cybersecurity Dive said only that the company did not disclose whether ransomware was involved. On August 2 the AlphV/BlackCat ransomware group took credit for the attack, according to The Record, claiming to hold sensitive documents belonging to senior company officials.

Tempur Sealy said it would notify regulators if it determined that customer or employee information had been compromised. The forensic investigation remained under way as of early August 2023.

Sources