German certification body GUTcert reported that unidentified attackers accessed parts of its IT environment on 5 September 2026 and allegedly exfiltrated about 640 GB of data from 6 to 9 September. The organization detected the intrusion overnight between 9 and 10 September, cut off identified attacker access on 10 September, and notified Berlin’s data-protection authority, the LKA, and Germany’s BSI on 11 September. Employees were informed on 14 September.
The attackers launched repeated extortion attempts from 12 to 20 September and sent GUTcert clients, contacts, auditors, and employees emails containing links to purported stolen data. GUTcert also identified and closed an unauthorized email session on 15 September; it said it had no evidence at that time of concurrent file-system access. Organizations that exchanged sensitive information with GUTcert should assess exposure, monitor for credential theft and targeted phishing, and validate the authenticity of breach-related communications.

See attribution, scope, and your downstream exposure.
14 events from the most recent confirmed update back to the earliest known activity.
GUTcert publicly reported the cybersecurity incident on its official website.
The attackers made fifth and sixth extortion attempts by emailing GUTcert clients, contacts, auditors, and employees links to download purportedly stolen data.
GUTcert published a dedicated page providing information about the security incident.
The attackers made a fourth extortion attempt from an external account.
The attackers made a third extortion attempt using an external email account.
GUTcert identified and immediately closed an unauthorized email session that had remained active. It reported no indication of simultaneous file-system access at that time.
The attackers made a second extortion attempt against GUTcert.
GUTcert informed all employees about the cybersecurity incident.
The attackers made their first extortion attempt. GUTcert did not respond.
GUTcert notified the Berlin data-protection authority, the LKA, and Germany’s Federal Office for Information Security (BSI) about the incident.
GUTcert terminated the attacker access it had identified following detection of the intrusion.
Unidentified third parties gained unauthorized access to parts of German certification body GUTcert’s IT systems.
GUTcert detected the attack overnight between 9 and 10 September during routine activity.
The attackers allegedly exfiltrated about 640 GB of data from GUTcert between 6 and 9 September.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.