Connect with us

Hi, what are you looking for?



Eurofins Scientific Paid Up in Response to Ransomware Attack: Report

Luxembourg-based laboratory testing services giant Eurofins Scientific reportedly paid the ransom demanded by cybercriminals following a successful ransomware attack that led to the company taking offline many of its systems and servers.

Luxembourg-based laboratory testing services giant Eurofins Scientific reportedly paid the ransom demanded by cybercriminals following a successful ransomware attack that led to the company taking offline many of its systems and servers.

Eurofins is an important provider of food, pharma and environmental laboratory testing services. The company, which also offers cybersecurity services through Eurofins Digital Testing, employs roughly 45,000 people for its more than 800 laboratories in 47 countries.

The company revealed in early June that some of its IT systems had been infected with a piece of ransomware; a new variant that evaded its cybersecurity solutions.

A few weeks later, the organization reported making good progress in restoring disrupted systems and attempted to minimize the impact of the incident, highlighting that there had been no evidence that confidential client data had been stolen.

“As of Monday June 17th, the vast majority of affected laboratories’ operations had been restored,” Eurofins stated in a press release issued in June 24. “The production and reporting IT systems of essentially all those that remained became operational again during the past week. Restoration operations are continuing for some less important back office and software development systems as well as in a few companies (representing less than 2% of the Group’s revenues) some specific procedures required before restart of certain activities that are anticipated to be completed by end of next week.”

However, the BBC reported on Friday that Eurofins had actually paid a ransom to the cybercriminals who targeted its systems. While the amount is unknown, it’s believed the ransom was paid sometime between June 10 and June 24.

SecurityWeek has reached out to Eurofins for confirmation and will update this article if the organization responds.

Advertisement. Scroll to continue reading.

According to the BBC, Eurofins is the UK’s biggest provider of forensic services, used in over 70,000 investigations every year. Police and other law enforcement agencies in the country stopped sending samples to Eurofins following the incident and court hearings have been reportedly postponed due to analysis results from Eurofins not being available.

Several important organizations have been hit by ransomware over the past year, including COSCONorsk Hydro, the UK Police Federation, and Aebi Schmidt.

UPDATE. Eurofins pointed SecurityWeek to its press releases and provided the following statement: Forensics investigations with the relevant authorities are ongoing so we cannot comment on speculative reports at this time.

Related: New Sodinokibi Ransomware Delivered via Oracle WebLogic Flaw

Related: GandCrab Ransomware Detected Targeting Manufacturing Firm

Related: Utah County Struck by Ransomware

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.


Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.


Expert Insights

Related Content


The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.


Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.


As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.


A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...


Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...