Recommended Free Tools
Rheinmetall said its military business was not affected by the ransomware attack detected on April 14, 2023. The company later confirmed that Black Basta was responsible. Its reported impact assessment concerned a different part of the business: the civilian operation serving industrial customers, particularly automotive companies.
What happened in the 2023 attack?
Rheinmetall said it detected the incident on April 14, 2023. In contemporaneous reporting, the company said the attack affected its civilian business serving industrial customers, particularly the automotive sector, while military operations continued. Rheinmetall later confirmed Black Basta was responsible, as reported by The Record on May 22, 2023 and SecurityWeek on May 23, 2023.
| Business area | Function described in reporting | Reported impact | Basis for the claim |
|---|---|---|---|
| Civilian operation | Industrial customers, particularly automotive | Rheinmetall said this business was affected. | Company statements reported by SecurityWeek and Reuters via MarketScreener. |
| Military business | Defense operations | Rheinmetall said it was not affected and continued operating. | The company’s reported assessment; the cited coverage does not independently verify it. |
Why did Rheinmetall say the military business was unaffected?
Rheinmetall’s explanation, quoted by SecurityWeek, was that the military business relied on “strictly separated IT infrastructure.” That is the company’s account of why the attack did not affect that area. The reporting cited here does not establish that an independent forensic audit verified the network separation or the impact assessment.
What was reported about Black Basta’s leak site?
SecurityWeek reported that Black Basta listed Rheinmetall on its leak site and displayed screenshots of material the group said it had obtained. The publication described images that appeared to show purchase orders, passport copies, technical schemes, confidentiality letters, non-disclosure agreements and other corporate documents. These were the group’s claims and displays as reported by SecurityWeek; they do not establish the full scope or sensitivity of any data exposure, or what was ultimately published.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
Were authorities investigating?
Tagesschau reported on April 14, 2023, that the Cologne public prosecutor’s office had opened an investigation. SecurityWeek later reported that Rheinmetall said it had informed authorities and filed a criminal complaint with the Cologne prosecutor’s office. Those reports establish that an investigation and complaint were reported, not its eventual findings.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How does this differ from Rheinmetall’s 2019 malware incident?
Rheinmetall announced a separate malware event in September 2019 affecting automotive plants in Brazil, Mexico and the United States. The company said production at those sites was significantly disrupted and estimated an adverse impact on operating results of EUR 3 million to EUR 4 million per week starting in week two. That was the company’s estimate at the time for the 2019 event, not a financial estimate for the 2023 ransomware attack. In its September 26, 2019 announcement, Rheinmetall also said other group IT systems were not affected in that earlier incident.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Rank #3
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




