Ransomware

Control Systems Firm PSI Struggles to Recover From Ransomware Attack

German control system solutions provider PSI Software says it is still recovering from a ransomware attack.

German control system solutions provider PSI Software says it is still recovering from a ransomware attack.

German control systems provider PSI Software this week announced that its systems are still down following a ransomware attack earlier this month.

The incident was initially disclosed on February 15, when the company announced that it proactively disconnected its systems from the internet, to prevent data exfiltration.

On Monday, the company updated its initial notification to reveal that ransomware was involved in the cyberattack and that it has yet to restore its internal IT infrastructure.

“As a result, all external connections and systems were successively shut down still in the night. We also shut down PSI’s mail system in the night, so that no mails have been sent from PSI systems since then,” the company said.

PSI also noted that it is still investigating the attack vector and that it has found no evidence that PSI systems at customer sites have been affected.

“According to current knowledge, there was no access to remote connections for the maintenance of customer systems,” the company said.

Advertisement. Scroll to continue reading.

According to PSI, its security team is still working on containing the incident and restoring the affected systems. The responsible authorities have been notified of the attack, the company also said.

Headquartered in Berlin, PSI Software provides control systems to major European energy suppliers. Its solutions cover control, monitoring, and optimization for electricity, gas, oil, heat, and water, including leak detection and location, network utilization, operational management, and pipeline management.

SecurityWeek has not observed any ransomware gang taking responsibility for the attack.

Related: Cactus Ransomware Group Confirms Hacking Schneider Electric

Related: Ransomware Group Takes Credit for LoanDepot, Prudential Financial Attacks

Related: Ransomware Attack Knocks 100 Romanian Hospitals Offline

Related Content

Ransomware

The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password.

Ransomware

Focusing on hacking law firms in the US, the ransomware group relies on fast flux to hide its C&C infrastructure.

Data Breaches

The non-bank lender discovered a ransomware attack nearly one year ago, but only recently completed its investigation.

Data Breaches

The Nitrogen ransomware group claims to have hacked the company’s systems, stealing 8TB of data, including confidential documents.

Data Breaches

The company took systems offline globally after hackers exfiltrated data and deployed file-encrypting ransomware.

Data Breaches

RansomHouse has published several screenshots to demonstrate access to internal Trellix services.

Nation-State

Likely perpetrated by MuddyWater, the attack combined social engineering, persistence, credential harvesting, and data theft.

Cybercrime

Deniss Zolotarjovs was directly involved in extortion strategies and in negotiations with victim companies.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version