Supply chain ⛓ Supply Chain

Primula Third-Party Breach (January 2024)

📅 2024-01-01 🏢 Tietoevry
Primary Source ↗

Incident Details

Akira ransomware hits cloud service Tietoevry; numerous Swedish customers affected. Finland-based Tietoevry said “one part of one of our Swedish datacenters” was attacked with Akira ransomware. Several high-profile customers were affected, including payroll and HR company Primula. Cloud hosting services provider Tietoevry announced that one of its datacenters in Sweden “was partially subject to a ransomware attack” this weekend, affecting numerous customers and forcing stores to close across the country. According to the Finland-based technology company’s statement on Monday , the attackers used the Akira ransomware-as-a-service tools. The incident was limited to “one part of one of our Swedish datacenters” and is believed to have only impacted services to some of Tietoevry’s customers in Sweden. Third-party company: Tietoevry.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Tietoevry
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-01-01 Breach occurred
  2. 2024-01-22 Publicly disclosed