Latest information on the cyberattack on GUTcert on
5 September 2026
Updated: 17 September 2026 at 12:19 h
If you have any questions, please contact us at incident@gut-cert.de.
Please contact us directly – our auditors are not the right people to contact in this matter.
Customer newsletter dated 16 September 2026
Dear Sir or Madam,
We wish to ensure maximum transparency for you and would therefore like to provide you with detailed information regarding the ongoing IT security incident at GUTcert. This includes the clear statement: We will not comply with the attackers’ demands.
Timeline of the incident
- 5 September 2026: Unknown third parties gained unauthorised access to parts of our IT systems
- 6–9 September 2026: During this period, approximately 640 GB of data was stolen.
- Night of 9–10 September 2026: The attack was detected late in the evening during a routine check. The attackers’ access points identified at that time were blocked on 10 September. On 15 September, as part of the ongoing investigation, an email session that was still active was detected and terminated. The forensic examination of possible further activity is ongoing.
- 11 September 2026: Report submitted to the Berlin Commissioner for Data Protection and Freedom of Information and to the State Criminal Police Office (LKA); we have also informed the Federal Office for Information Security (BSI) on a voluntary basis.
- 12 September 2026: First attempt at blackmail by the attackers, to which we have not responded to date and will not respond.
- 14 September 2026: All staff were informed about the incident, including a list of FAQs with guidance on how to communicate the matter.
- 14 September 2026: Engaged an external IT forensic expert and informed all customers and auditors.
- 15 September 2026, afternoon: Second attempt at blackmail by the attackers. Subsequently, an unauthorised email session that was still active was detected and immediately terminated. According to the current state of the investigation, there is no evidence to suggest that this session also provided ongoing access to our file systems at that time.
Due to the temporary access to our email system, we ask you, as a precaution, to exercise increased vigilance regarding emails that appear to originate from GUTcert – particularly in the case of unusual attachments, links or requests for payment. If in doubt, please verify the message by telephone using a GUTcert number you already know.
What was stolen?
Based on the information currently available, the following categories of data are affected. We will inform you immediately as soon as we have further information:
- Personal data of our employees
- GUTcert’s financial and tax-related data
- Customer data stored in our internal project files, including:
- Contact details
- possibly employee data (currently still being investigated)
- Audit records and audit reports
- Management system and procedural documentation
- Technical information and details of vulnerabilities
- Customer information
- Possibly login details, certificates or other confidential information (currently under review)
What is not affected, based on current information?
- According to the current status of the investigation, there is no evidence of unauthorised access to the Nextcloud platform or the data stored there. Data that was stored exclusively in Nextcloud and was not transferred to other affected systems is, as far as we are currently aware, not included in the confirmed data breach.
- Based on the current state of the investigation, there is no evidence to suggest that separate sets of personal data belonging to our auditors were part of the confirmed data breach from the internal project repositories.
The full analysis of exactly which data has been affected is still ongoing; we will provide you with further updates on this as soon as reliable results are available.
To provide you with the necessary information for your own risk, reporting and regulatory assessments, we have compiled a list of FAQs below.
We are aware that this news is cause for concern. From the outset, we have prioritised full transparency towards our stakeholders, in particular our clients and auditors, and we will continue to do so. If you have any questions, please contact us at incident@gut-cert.de or, as usual, via the usual email addresses and telephone numbers.
For data protection enquiries and further information regarding the potential impact on personal data, please contact our Data Protection Officer at datenschutz@gut-cert.de.
The tremendous support and understanding that many of you have shown us so far has been a great help to us, and we would like to take this opportunity to express our sincere thanks.
Yours faithfully
GUTcert
FAQ on the GUTcert IT security incident – as at 16 September 2026
Below is a selection of the measures we have already taken:
- Compromised user accounts deactivated
- All VPN certificates replaced
- Automatic system monitoring enhanced
- Kerberos KRBTGT account reset twice
- All admin credentials and SSH keys changed
- Compromised initial system decommissioned
- Domain CA certificate and other certificates reissued
- Staff made aware of the issue
- We are working in close consultation with a team of forensic experts to define measures and implement them as a matter of priority. These include, amongst other things, adjustments to our access control policies, greater system segregation and a fundamental shift towards the Zero Trust approach.
- We are also in close contact with the State Criminal Police Office (LKA) and the BSI’s National Situation Centre.
When your organisation reports incidents to the BSI, please refer to the security incident at GUTcert.
Any information stored in the internal project repositories affected by the data breach may be compromised:
e.g. audit reports, identified deficiencies (particularly relevant to 27001/ITSK/KRITIS), evidence in accordance with FL076 (articles of association or general evidence of group affiliations, management reviews, network structure diagrams, SLAs or similar, organisation charts, list of business premises), and certificates that should not be listed on the GUTcert website.
According to the current state of the investigation, there is no evidence of unauthorised access to the Nextcloud platform or Nextcloud login details.
At this stage, we are not yet able to state definitively whether, or to what extent, your organisation has been affected. Should it transpire that specific data has been compromised, we will inform you immediately.
A significant data breach has been confirmed.
GUTcert staff and – depending on the specific documents in question – contact persons, employees, system administrators and consultants at our clients’ and partners’ organisations.
Particularly in the area of ISMS, there are vulnerabilities that can be specifically (technically) exploited. In all areas, the information can be used for social engineering and spear-phishing attacks.
For individuals who may be affected, there are particular risks arising from targeted phishing and social engineering attacks, as well as unauthorised attempts to make contact. Furthermore, where login details or other authentication information were part of the data breach, unauthorised access to associated systems or accounts cannot be ruled out.
Data Protection Law
GUTcert has already notified the relevant data protection supervisory authority of the incident in a preliminary report. The data protection assessment will be updated as further information becomes available.
Further investigations are currently underway to determine which specific individuals have been affected by the data breach and what risks this entails in each case.
Where GUTcert processes personal data in individual cases as a data processor, the obligations to inform the relevant data controller under Article 33(2) of the GDPR, as well as the relevant contractual provisions, apply in addition.
Initial information regarding the security incident and the potential data breach known at the time was sent to our customers on 14 September 2026. The processing activities concerned and the relevant data protection roles are currently being further examined.
Where processing activities are classified as data processing on behalf of a controller and it cannot be ruled out that the personal data processed in this context has been affected, we will provide the relevant controllers with further information and will continuously make available to them the findings necessary for their own assessment and any required notifications.
If your organisation falls
under the BSIG / NIS2 regulations The security incident that occurred at GUTcert may, depending on the nature and scope of the specific data affected and its significance for your systems and services, trigger a need for your own investigation and, where necessary, reporting.
Particularly important and important organisations should therefore assess at short notice whether the specific impact meets the criteria for a significant security incident within the meaning of the BSIG.
In particular, where information from the areas of information security, network and system architecture, vulnerabilities, emergency management or other security-related evidence may be affected, we recommend an immediate assessment by the departments within your organisation responsible for information security and compliance.
Whether a statutory reporting obligation exists depends on the regulatory classification and the specific implications for the company in question, and cannot be assessed by GUTcert on a blanket basis for individual clients.
For certain organisations in the financial sector, the sector-specific requirements of DORA apply in place of the reporting obligations under Section 32 of the BSIG; further regulatory obligations may also apply.
If your organisation is
an operator of a critical infrastructure, it should also assess whether the specific incident has, or could have, an impact on the critical infrastructure or the provision of a critical service, and what additional information or reporting obligations may arise, in particular under Section 32( 3 of the BSIG and, where applicable, under other sector-specific regulations.
This assessment also depends on the specific circumstances of the operator in question.
The attackers’ access points identified when the incident was discovered were blocked, and the relevant access credentials and certificates were either replaced or revoked.
On 15 September 2026, as part of the ongoing investigation, an additional, still-active email session was detected and immediately terminated.
The forensic investigation into possible further persistence mechanisms is ongoing. We are therefore unable at this stage to provide definitive forensic confirmation that all access points created during the attack have been fully reconstructed.
We particularly recommend:
- increased vigilance regarding emails, attachments, links and payment requests that purport to be from GUTcert
- verification via an independent communication channel in the event of unusual or security-related messages
- Checking whether technical information received from or shared with GUTcert could be misused to launch attacks on your own infrastructure
- where appropriate, changing access details or authorisations as a precautionary measure, provided these have been disclosed to GUTcert or may have been included in documents submitted
- an internal assessment of any potential statutory, regulatory and contractual reporting obligations
A significant data breach has been confirmed. A forensic investigation is still underway to determine exactly which companies and data sets are affected, and to what extent.
Given the blackmail threats made against GUTcert, we must expect that the stolen data may be published or otherwise misused. At present, we can neither confirm nor rule out the possibility of such data actually being published.
- According to the current state of the investigation, unauthorised access to parts of our IT systems began on 5 September 2026.
- According to the current state of the investigation, the confirmed data breach took place between 6 September and 9 September 2026.
- On 10 September, the initially identified access routes were blocked. On 15 September, an additional, still-active email session was detected and terminated.
- Further forensic reconstruction of the entire period and any other possible means of access is ongoing.
At present, we cannot entirely rule out the possibility that documents in the affected dataset contained login details, certificates, access links or other technical authorisation information.
We do not currently have any reliable evidence that such information has actually been misused in relation to individual customers.
If your organisation has shared such information with GUTcert, we recommend that you carry out a precautionary review and, where necessary, renew the relevant authorisations.
Yes. On 15 September 2026, at least one unauthorised email session that was still active was detected and terminated.
As it is currently not possible to definitively determine the exact start time of this unauthorised access, any security-related or unusual messages sent from GUTcert accounts between 5 September and 15 September 2026 should, if in doubt, be verified via an independent communication channel.
We are currently working with our external IT forensics team to continuously review and secure our communication channels.
Where a separate communication channel is required for particularly sensitive information, we will arrange this with you on a case-by-case basis.
Please do not send any new login details or other highly sensitive information via unencrypted email at this time.
Yes. As soon as we have reliable information regarding the specific impact on individual customers or data sets, we will inform the affected companies without delay.
Regardless of this, we will communicate any significant new information regarding the incident in an appropriate manner.
Technical and organisational security measures were in place for the affected systems, including role- and authorisation-based access restrictions, as well as network and system security measures.
The ongoing forensic investigation is examining which security mechanisms were bypassed in this specific attack and which measures need to be adjusted or expanded.We do not wish to pre-empt the final technical assessment and will communicate further reliable findings in this regard.
No. At the time of the incident, multi-factor authentication was not mandatory for accessing Nextcloud.
According to the current state of the investigation, there is no evidence to suggest that the Nextcloud platform or Nextcloud login credentials were involved in the attack.
Regardless of this, we are currently reviewing and strengthening the authentication and access protection measures for this system.
Were there any local synchronisations or copies of the Nextcloud data on the affected systems?
To the best of our knowledge, there was no general mirroring or synchronisation of the Nextcloud data onto the file systems affected by the confirmed data breach.
Regular backups of Nextcloud are maintained separately from this.
According to the current state of the investigation, there is no evidence of unauthorised access to our Nextcloud platform itself. The investigation is continuing as part of the ongoing forensic analysis.
The role under data protection law depends on the specific processing activity and cannot be answered in general terms for all personal data transmitted in the context of a certification or audit.
GUTcert is currently reviewing the processing activities in question and the respective contractual bases.
Where GUTcert itself determines the purposes and essential means of processing, it acts as the data controller under data protection law. Where personal data is processed exclusively on behalf of and in accordance with the documented instructions of a client, we assess whether this constitutes processing on behalf of a client in accordance with Article 28 of the GDPR and review the relevant contractual provisions.
The contractual partners concerned will receive the information necessary for their own data protection assessment.
GUTcert has commissioned an external, specialist IT forensics service provider to investigate the incident.
The forensic investigation is still ongoing. A final report is not yet available.
We will provide our customers with the relevant and reliably verified findings necessary for them to assess the specific impact on them.
We do not currently intend to disclose the full internal forensic reports, as these may contain, amongst other things, security-critical information, personal data and information relating to other affected third parties.