preloader

· digital-security europe ransomware supply-chain nis2 incident-response manufacturing compliance

The Group That Writes Europe’s Safety Standards Just Became a Ransomware Target Itself

Source: RedPacket Security

Ransomware groups usually go after companies with money and a deadline pressure they can exploit, hospitals, logistics firms, manufacturers mid-shipment. CEN and CENELEC do not fit that profile. They are the European Committee for Standardization and the European Committee for Electrotechnical Standardization, the Brussels-headquartered bodies that write and publish the voluntary technical standards referenced across engineering, manufacturing, energy and electrotechnical products sold throughout the EU and EEA. On 1 August, the extortion group coinbasecartel listed both organisations as victims on its leak site, threatening to publish sensitive data unless a negotiation begins.

What is actually confirmed, and what is not

As of this week, neither CEN nor CENELEC has issued a public statement confirming or denying the claim. The leak site listing does not include a data sample, a stated volume of records, a ransom figure, or confirmation of whether systems were encrypted or only exfiltrated. Coinbasecartel, first observed in September 2025, is known specifically for skipping encryption in favour of pure data-theft extortion, using staged leak-site disclosures to pressure victims into contact. That pattern makes the claim credible enough to take seriously without yet being independently verifiable, which is precisely the uncertainty window every organisation named on a leak site has to manage, whether the claim turns out to be accurate or exaggerated.

Why the target matters more than the confirmation

Regardless of how this specific claim resolves, the choice of target is worth sitting with. CEN and CENELEC do not hold customer payment data or trade secrets in the way a typical ransomware victim does. What they hold is the reference documentation that thousands of European manufacturers build compliance programmes around, standards that determine what “safe” and “interoperable” mean for products sold across the continent. An organisation upstream of that many downstream dependents is a high-leverage target for exactly the same reason a software supply chain vendor is: compromising one node can create doubt, or worse, real disruption, across everyone who relies on it without ever touching those downstream organisations directly.

The lesson that applies before the facts are settled

European manufacturers and engineering firms that reference CEN or CENELEC standards in their own compliance documentation do not need to wait for full confirmation to ask a useful question: does our incident response plan account for a disruption at a standards body or certification authority we depend on but do not control? NIS2’s supply chain risk provisions already push organisations toward exactly this kind of dependency mapping, and a leak-site claim against an EU standards body is as good a prompt as any to test whether that mapping actually covers non-obvious upstream dependencies, not just direct suppliers and cloud vendors.

If your organisation wants help mapping upstream dependencies that fall outside a typical vendor risk register, or building an incident response plan that accounts for disruption at institutions you rely on but cannot audit directly, contact Excello Digital. We help European organisations find the dependencies their existing risk assessments miss.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!