Latest information on the cyber attack on GUTcert on 5 September 2026

Updated: 7 October 2026 at 9.37 am

go to FAQ

On this page, you will find regularly updated information on the cyber attack on GUTcert – to ensure maximum transparency. A word of note: we will not comply with the attackers’ demands.

Our FAQs are also constantly being expanded and updated.

If you have any questions, please contact us at incident@gut-cert.de.

For questions regarding data protection and further information on whether your personal data may have been affected, please contact our Data Protection Officer at datenschutz@gut-cert.de.

  • Our ability to work has been and remains assured.
  • Please always contact us directly – our auditors are not the appropriate points of contact in this matter.

Below, we have listed the sequence of events surrounding the security incident for you, in reverse chronological order.

Order of events

6 October 2026, noon: eighth and ninth attempts at blackmail. Additional emails are sent to numerous customers and contacts. The criminals repeat their demands for payment and threaten to release additional information. They use threatening language to try to further increase the pressure. The approach follows a familiar pattern: data is stolen and then used as leverage to demand money. Our decision is firm: We will not comply with the demands of the criminals. Further threats and allegations will not change this. Our focus is on implementing the necessary protective measures for our customers and our IT systems, as well as on cooperating with the relevant investigative authorities. At the same time, we are working on implementing an information security management system in accordance with ISO/IEC 27001 to systematically further develop our security measures.

5 October 2026, afternoon: seventh attempt at blackmail. The email is once again being sent to many of our customers and contacts. The criminals behind the cyberattack are demanding money, pretending that they will delete the data afterward. We ask you not to respond to such dubious proposals, to forward these emails to us, and to delete them from your account.

20 September 2026, afternoon: fifth and sixth attempts at blackmail. The email is being sent to many of our customers, contacts, auditors and staff. The message contains download links which conceal illegally copied data stolen from GUTcert.

17 September 2026, morning: Fourth attempt at blackmail, again from an external email account.

17 September 2026: A landing page regarding the security incident goes live on our website to keep all stakeholders equally informed.

16 September 2026, afternoon: Third blackmail attempt by the attackers. This time sent from an external email account.

15 September 2026, afternoon: Second attempt at blackmail by the attackers. Subsequently, an unauthorised email session that was still active was detected and terminated immediately. According to the current state of the investigation, there is no evidence to suggest that this session provided ongoing access to our file systems at that time.

On 15 September, in the course of the ongoing investigation, an active email session was detected and terminated. The forensic analysis of possible further activity is ongoing.

15 September 2026: Reports to other institutions, including DAkkS.

14 September 2026: All staff were informed about the incident.

12 September 2026: First attempt at blackmail by the attackers, to which we have not responded to date and will not respond.

11 September 2026: Report submitted to the Berlin Commissioner for Data Protection and Freedom of Information and to the State Criminal Police Office (LKA); additional information provided to the Federal Office for Information Security (BSI).

Night of 9–10 September 2026: The attack was detected late in the evening during a routine check. The attackers’ access points identified at that time were blocked on 10 September.

6–9 September 2026: During this period, approximately 640 GB of data is stolen.

5 September 2026: Unknown third parties gain unauthorised access to parts of our IT system.
    

FAQ on the GUTcert IT security incident

No. We reported the security incident to DAkkS on 15 September 2026. Subsequently, the office audit scheduled for 21–25 September – which had been planned prior to the IT incident – was expanded to include an assessment of our certification body’s operational capability and the security of customer data.

The audit was carried out by the assessor who had also reviewed our accreditation in the areas of ISMS and ITSK.

The outcome was that GUTcert’s operational capability was not impaired by the security incident. With regard to the security of customer data, the measures we had already implemented or commenced were accepted, and no further immediate measures were required.

  • According to the current state of the investigation, unauthorised access to parts of our IT systems began on 5 September 2026.
  • According to the current state of the investigation, the confirmed data breach took place between 6 September and 9 September 2026.
  • On 10 September, the initially identified access routes were blocked. On 15 September, an additional, still-active email session was detected and terminated.
  • Further forensic reconstruction of the entire period and any other possible means of access is ongoing.

Below is a selection of the measures we have already taken:

  • Compromised user accounts deactivated
  • All VPN certificates replaced
  • Automatic system monitoring enhanced
  • Kerberos KRBTGT account reset twice
  • All admin credentials and SSH keys changed
  • Compromised initial system decommissioned
  • Domain CA certificate and other certificates reissued
  • Staff made aware of the issue

  • We are working in close consultation with a team of forensic experts to define measures and implement them as a matter of priority. These include, amongst other things, adjustments to our authorisation policies, stronger system segregations and a fundamental shift towards the Zero Trust approach.
  • We are also in close contact with the State Criminal Police Office (LKA) and the BSI’s National Situation Centre.
  • We have introduced stricter authorisations regarding access arrangements for our internal and external IT administrators and consultants.
  • We are implementing further measures to, amongst other things, minimise access to specific accounts.
  • Stricter restrictions on staff access to our customers’ data are currently being put in place, as is a comprehensive roll-out of multi-factor authentication (e.g. using OTP).
  • When your organisation reports incidents to the BSI, please refer to the security incident at GUTcert.

When your organisation reports this incident to the BSI, please refer to the security incident at GUTcert.

The attackers’ access points identified upon discovery of the incident were blocked, and the relevant access credentials and certificates were either replaced or revoked.

On 15 September 2026, as part of the ongoing investigation, an additional, still-active email session was detected and immediately terminated.

The forensic investigation into possible further persistence mechanisms is ongoing. We are therefore unable to provide a definitive forensic confirmation at this stage.

However, a recent interim report has confirmed to GUTcert that, based on analyses to date – including the assessment of the security incident – there are currently no signs of an active security incident and no ongoing suspicious activity on the GUTcert network.

Yes. A data breach has been confirmed.

A data breach has been confirmed. A forensic investigation is still underway to determine exactly which companies and data sets are affected, and to what extent.

Due to the blackmail directed at GUTcert, we must expect that stolen data may be published or otherwise misused. At present, we can neither confirm nor rule out the possibility of such data actually being published.

GUTcert has commissioned an external, specialist IT forensics service provider to investigate the incident.

The forensic investigation is still ongoing. A final report is not yet available.
We will provide our customers with the relevant and reliably verified findings necessary for them to assess the specific impact on them.

We do not currently intend to disclose the full internal forensic reports, as these may contain, amongst other things, security-critical information, personal data and information relating to other affected third parties.

Any information stored in the internal project repositories affected by the data breach may be compromised:

e.g. audit reports, identified deficiencies (particularly relevant to 27001/ITSK/KRITIS), evidence in accordance with FL076 (articles of association or general evidence of group affiliations, management reviews, network structure diagrams, SLAs or similar, organisation charts, list of business premises), and certificates that should not be listed on the GUTcert website.

According to the current state of the investigation, there is no evidence of unauthorised access to the Nextcloud platform or Nextcloud login details.

At this stage, we are not yet able to state definitively whether, or to what extent, your organisation has been affected. Should it transpire that specific data has been compromised, we will inform you immediately.

Yes. As soon as we have reliable information regarding the specific impact on individual customers or data sets, we will inform the affected companies without delay.

Regardless of this, we will communicate any significant new information regarding the incident in an appropriate manner.

Yes. On 15 September 2026, at least one unauthorised email session that was still active was detected and terminated.

As it is currently not possible to definitively determine the exact start time of this unauthorised access, any security-related or unusual messages sent from GUTcert accounts between 5 September and 15 September 2026 should, if in doubt, be verified via an independent communication channel.

We are currently working with our external IT forensics team to continuously review and secure our communication channels.

Based on analyses carried out to date, there are currently no indications of any ongoing suspicious activity within our IT systems.

Against this background, we would ask you to adjust or remove any blocks or blacklist entries you may have set up for emails from our company, so that we can continue our ongoing project work and communication with you as usual.

Where a separate communication channel is required for particularly sensitive information, we will arrange this with you on a case-by-case basis.

At present, we cannot entirely rule out the possibility that documents in the affected dataset contained login details, certificates, access links or other technical authorisation information.

We do not currently have any reliable evidence that such information has actually been misused in relation to individual customers.

If your organisation has shared such information with GUTcert, we recommend that you carry out a precautionary review and, where necessary, renew the relevant authorisations.

Technical and organisational security measures were in place for the affected systems, including role- and authorisation-based access restrictions, as well as network and system security measures.

The ongoing forensic investigation is examining which security mechanisms were bypassed in this specific attack and which measures need to be adjusted or expanded.We do not wish to pre-empt the final technical assessment and will communicate further reliable findings in this regard.

No. At the time of the incident, multi-factor authentication was not mandatory for accessing Nextcloud.

According to the current state of the investigation, there is no evidence to suggest that the Nextcloud platform or Nextcloud login credentials were involved in the attack.

Regardless of this, we are currently reviewing and strengthening the authentication and access protection measures for this system.

Were there any local synchronisations or copies of the Nextcloud data on the affected systems?
To the best of our knowledge, there was no general mirroring or synchronisation of the Nextcloud data onto the file systems affected by the confirmed data breach.

Regular backups of Nextcloud are maintained separately from this.

According to the current state of the investigation, there is no evidence of unauthorised access to our Nextcloud platform itself. The investigation is continuing as part of the ongoing forensic analysis.

As far as we are currently aware, there was no general mirroring or synchronisation of the Nextcloud data onto the file systems affected by the confirmed data breach.

Regular backups of Nextcloud are maintained separately from this. 

According to the current state of the investigation, there is no evidence of unauthorised access to our Nextcloud platform itself. The investigation is continuing as part of the ongoing forensic analysis.

We particularly recommend:

  • increased vigilance regarding emails, attachments, links and payment requests that purport to be from GUTcert
  • verification via an independent communication channel in the event of unusual or security-related messages
  • Checking whether technical information received from or shared with GUTcert could be misused to launch attacks on your own infrastructure
  • where appropriate, changing access details or authorisations as a precautionary measure, provided these have been disclosed to GUTcert or may have been included in documents submitted
  • an internal assessment of any potential statutory, regulatory and contractual reporting obligations

Data Protection Law
GUTcert has already notified the relevant data protection supervisory authority of the incident in a preliminary report. The data protection assessment will be updated as further information becomes available.

Further investigations are currently underway to determine which specific individuals have been affected by the data breach and what risks this entails in each case.

Where GUTcert processes personal data in individual cases as a data processor, the obligations to inform the relevant data controller under Article 33(2) of the GDPR, as well as the relevant contractual provisions, apply in addition.

Initial information regarding the security incident and the potential data breach known at the time was sent to our customers on 14 September 2026. The processing activities concerned and the relevant data protection roles are currently being further examined.

Where processing activities are classified as data processing on behalf of a controller and it cannot be ruled out that the personal data processed in this context has been affected, we will provide the relevant controllers with further information and will continuously make available to them the findings necessary for their own assessment and any required notifications.

If your organisation falls
under the BSIG / NIS2 regulations The security incident that occurred at GUTcert may, depending on the nature and scope of the specific data affected and its significance for your systems and services, trigger a need for your own investigation and, where necessary, reporting.

Particularly important and important organisations should therefore assess at short notice whether the specific impact meets the criteria for a significant security incident within the meaning of the BSIG.

In particular, where information from the areas of information security, network and system architecture, vulnerabilities, emergency management or other security-related evidence may be affected, we recommend an immediate assessment by the departments within your organisation responsible for information security and compliance.

Whether a statutory reporting obligation exists depends on the regulatory classification and the specific implications for the company in question, and cannot be assessed by GUTcert on a blanket basis for individual clients.

For certain organisations in the financial sector, the sector-specific requirements of DORA apply in place of the reporting obligations under Section 32 of the BSIG; further regulatory obligations may also apply.

If your organisation is
an operator of a critical infrastructure, it should also assess whether the specific incident has, or could have, an impact on the critical infrastructure or the provision of a critical service, and what additional information or reporting obligations may arise, in particular under Section 32( 3 of the BSIG and, where applicable, under other sector-specific regulations.

This assessment also depends on the specific circumstances of the operator in question.

The role under data protection law depends on the specific processing activity and cannot be answered in general terms for all personal data transmitted in the context of a certification or audit.

GUTcert is currently reviewing the processing activities in question and the respective contractual bases.

Where GUTcert itself determines the purposes and essential means of processing, it acts as the data controller under data protection law. Where personal data is processed exclusively on behalf of and in accordance with the documented instructions of a client, we assess whether this constitutes processing on behalf of a client in accordance with Article 28 of the GDPR and review the relevant contractual provisions.

The contractual partners concerned will receive the information necessary for their own data protection assessment.

In individual cases, contact information (e.g., name, phone number, email address, mailing address) may be affected, provided that such information has been provided to us.

Depending on the nature and scope of the data actually affected, the following risks, in particular, may arise:

  • targeted phishing and social engineering attempts using information from your previous employment
  • attempts to pose as an employee or service provider of Berlin Cert when contacting you
  • misuse of any bank account details that may have been compromised
  • where such data is held, the misuse of personal data for the purpose of identity fraud.

We cannot currently rule out the possibility that, as a result of the incident, you may receive targeted messages, phone calls or other forms of contact that refer to information relating to your previous employment.

Please be particularly vigilant in the coming days regarding unexpected emails, phone calls, text messages or other communications that make reference to Berlin Cert or your previous employment.

In particular, do not open any unexpected attachments and do not follow any links if you have any doubts about the authenticity of a message. Do not disclose any passwords, login details or other confidential information in response to such requests.

If your bank details may be affected, we also recommend that you check your bank statements and account transactions carefully for any irregularities.

If you have concrete grounds for suspecting that your personal data has been misused, you can contact us and, if necessary, the police or another relevant authority.

GUTcert staff and – depending on the specific documents in question – contact persons, employees, system administrators and consultants at our clients’ and partners’ organisations.

Particularly in the area of ISMS, there are vulnerabilities that can be specifically (technically) exploited.  In all areas, the information can be used for social engineering and spear-phishing attacks.

For individuals who may be affected, there are particular risks arising from targeted phishing and social engineering attacks, as well as unauthorised attempts to make contact. Furthermore, where login details or other authentication information were part of the data breach, unauthorised access to associated systems or accounts cannot be ruled out.