Description

PSI Software, a Germany-based vendor specializing in critical infrastructure software and logistics platforms, has been operating at reduced capacity since detecting a ransomware attack last Thursday. The intrusion affected PSI's internal IT infrastructure, prompting the company to immediately shut down all external connections and systems. Currently, the company's website is only partially accessible, with the remainder offline. In response to the attack, PSI is actively investigating the attack vector to ascertain the full extent of the breach. While the company has taken precautionary measures, including shutting down its email system following the detection of suspicious network activity on February 15, there is no evidence to suggest that PSI systems deployed at customer sites have been compromised. PSI has also engaged with German authorities and external cybersecurity experts to address the incident and mitigate further risks. This incident occurs amidst a surge in malicious activities targeting critical infrastructure worldwide, prompting concerns about the potential vulnerabilities in their IT environments. PSI Software, which provides control systems for various critical sectors such as energy management, operational oversight, and pipeline monitoring, has subsidiaries in multiple countries, including the United States. The company's supply chain includes procurement from major U.S.-based enterprise vendors like IBM, Microsoft, Oracle, and SAP. The attack on PSI Software underscores the growing threat landscape faced by critical infrastructure providers. With federal cyber officials issuing warnings about state-linked actors, such as those associated with China, prepositioning themselves for future disruptions, the need for enhanced cybersecurity measures and vigilance within the critical infrastructure sector has never been more urgent.