SHINDO2

Okuma

RansomwareSize not disclosed

POSSIBLE LEAKTrade secretsInvestigating

Open in the live monitor ▶
Disclosed
Sep 25, 2025
Detected
Sep 20, 2025
Detection to disclosure
5 days
Leak
Leak possible
Type
Ransomware
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

UnspecifiedEmployee personal data
Business dataConfidential information

Who is affected

  • Employees

Cause

Data on servers of German subsidiary Okuma Europe (OEG) was encrypted by ransomware

Timeline

  1. Detected
  2. Reported to German authorities and police
  3. First disclosure

Response

  • Forensic investigation

What you should do

  1. Expect targeted phishing posing as HR or interview contacts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Offline backups with restore drills; segment the network
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources