Year2023 |
MonthApril |
Reference number20230409 |
Impact areaShore |
Incident locationDenmark |
Incident countryDenmark |
Victim countryDenmark |
Victim identityDESMI |
Victim TypeCompany office |
MethodRansomware |
In April 2023, DESMI, a global pump solutions company based in Denmark, experienced a ransomware attack by the Clop gang. The attack led to the shutdown of all IT systems, but fortunately, the ERP and finance systems were not compromised, and production sites in China, India, America, and Denmark continued to operate without disturbances. The attack exploited the CVE-2023-34362 MOVEit vulnerability and occurred during the COVID-19 pandemic when employees were working from home. DESMI's CEO, Henrik Sørensen, confirmed that the company has no plans to pay the ransom. Third-party cybersecurity experts were hired to investigate and restore IT services. The incident has been reported to the authorities and Danish Police, and DESMI is notifying its customers and business partners about the breach. The company is focused on minimizing customer impact and expects to have systems operational within a couple of weeks.