AkzoNobel, one of the world’s largest paint manufacturers, disclosed a cyberattack affecting operations at a U.S. site and later confirmed that the incident also involved a data breach. The company said it detected unauthorized activity in its environment and took affected systems offline as part of its response, while working to contain the intrusion and assess the impact on business operations.
Public reporting indicates the incident was limited to a U.S. location rather than the company’s broader global network, though AkzoNobel has not released detailed technical indicators or attributed the attack to a specific threat actor. The company said its investigation was ongoing, with external cybersecurity specialists engaged to determine what data was accessed and to support remediation and recovery efforts.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting described the incident as a data breach involving AkzoNobel's U.S. site. This reflected a public disclosure that data exposure was part of the impact of the previously confirmed cyberattack.
AkzoNobel confirmed that it experienced a cyberattack impacting one of its U.S. locations. The company said it took affected systems offline and began investigating the incident.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.