Hans & Jos. Kronenberg GmbH has made door locks, switches, control panels and LED lighting for the elevator industry since 1932, the kind of specialised component manufacturer that sits several layers back from any building’s day-to-day operator. On 3 August, the Payload ransomware group added the Bergisch Gladbach company to its leak site, claiming 54GB of exfiltrated internal files and giving the company six to seven days before publication.
A vendor nobody downstream chose directly
No building manager, no property owner, no elevator maintenance contractor picked Kronenberg as a supplier in any meaningful sense. They chose an elevator installer or manufacturer, who chose Kronenberg for a specific component, several purchasing decisions removed from the people whose buildings ultimately run that part. That is the structural problem NIS2’s expanded supply chain requirements were designed for: risk that accumulates at a tier most organisations never directly assess, surfacing only when the vendor two or three steps removed shows up on a leak site.
Elevator components sit closer to safety than most IT supply chains
What makes this incident worth attention beyond a routine manufacturing breach is what Kronenberg actually makes: door locks and control systems, components with a direct relationship to how an elevator behaves mechanically and electronically. A breach at a company like this raises two separate questions rather than one. The first is the familiar one, whose personal or business data was in that 54GB. The second is less familiar and harder to dismiss: whether design files, firmware, or control system documentation for safety-relevant components were part of what was taken, and what that means for the integrity of products already installed in buildings across Europe.
What this means for anyone above Kronenberg in the chain
If your organisation manufactures, installs, or maintains equipment that incorporates third-party components, mechanical or electronic, this is a prompt to check whether any of your own suppliers make products where a data breach could plausibly compromise product integrity, not just customer records. NIS2’s essential and important entity obligations increasingly expect organisations to map that kind of dependency, not just their direct data processors, and a component vendor breach is a concrete example regulators will point to when asking what your supply chain risk assessment actually covers.
If your business relies on suppliers several tiers removed from your own systems, or you need a supply chain risk assessment that goes beyond checking whether your direct vendors have a security policy, contact Excello Digital. We help European manufacturers and operators map dependencies that data protection questionnaires alone will not surface.
