Six Weeks of Inactivity and 37 Years of History Lost: Cyberattack Forces German Textile Firm ZEGO into Bankruptcy
A devastating cyberattack has forced the long-established German textile company ZEGO Textilveredelungszentrum into bankruptcy proceedings after nearly six weeks without production, effectively ending 37 years of operations.
The Bavarian firm, which specialized in the finishing and processing of fabrics for the automotive industry, manufacturers of workwear, and producers of technical textiles, was unable to withstand the financial consequences of the prolonged shutdown.
The attack occurred on 29 March 2026 and brought production to a near-complete halt for almost six weeks. Company leadership explored multiple avenues to offset losses and keep the business afloat, but the extended downtime created an overwhelming financial burden that proved impossible to overcome.
Managing Director Johannes Zenglein described the move to seek creditor protection as one of the most painful decisions in the company’s history, stating that the attack had so severely damaged ZEGO’s financial position that continuing operations without insolvency proceedings was no longer viable.
The company has not disclosed the nature of the attack. It remains unknown whether the perpetrators used ransomware, who was responsible, or whether any customer or employee data was accessed. Management has only confirmed that the production stoppage itself placed the enterprise on the verge of closure.
The initiation of bankruptcy proceedings does not necessarily mean the final liquidation of ZEGO. The company intends to maintain production activities while insolvency administrators search for ways to restructure the business, protect jobs, and retain clients and suppliers.
Cyberattacks have previously disrupted factories and production lines, yet companies rarely acknowledge that operational downtime was the direct cause of their collapse. One of the most prominent examples is the bankruptcy of British logistics provider KNP Logistics, which operated for 158 years until attackers gained access via an employee password, encrypted systems, and left more than 700 people without work. Payment of the ransom failed to save the enterprise.
Related articles
Sorry Ransomware Exploits cPanel Vulnerability to Directly Lock Linux Servers in Multiple Chinese Incidents
China's National Computer Virus Emergency Response Center has issued a warning about the Sorry ransomware, which targets exposed Linux web servers through a cPanel authorization vulnerability. The Go-based malware gains root access without any phishing or user interaction, disguises itself as the legitimate sshd process, and follows a six-stage attack chain that includes data exfiltration before encryption. It terminates databases, security tools, and backup services, then uses AES and RSA to encrypt files with a .sorry extension while demanding ransom via an encrypted communication tool. The campaign specifically affects small and medium-sized enterprises running cPanel on mainstream Linux distributions, including domestic Xinchuang systems. Attackers also scan internal networks for weak SSH credentials to spread laterally. The center urges immediate patching of cPanel, exposure reduction, strong passwords, offline backups, and avoidance of fake decryptors.
China Warns of New 'Sorry' Ransomware Targeting Exposed Linux Web Servers via cPanel Vulnerability CVE-2026-41940
China's National Computer Virus Emergency Response Center has issued an official alert after multiple incidents of the newly discovered 'Sorry' ransomware family struck Linux Web servers inside the country. The Go-language malware specifically targets internet-exposed servers running vulnerable versions of WebPros cPanel and can also run on domestic Xinchuang operating systems. Attackers exploit authorization flaw CVE-2026-41940 (CNNVD-202604-5641) to gain access, deploy the ransomware disguised as sshd processes, kill backup and security services, exfiltrate data, and encrypt files with AES and RSA before scanning for weak SSH credentials to spread laterally. The advisory states that no reliable decryption method currently exists once files receive the .sorry extension. Organizations are urged to immediately audit cPanel versions, inspect processes, restrict management interfaces, eliminate weak passwords on ports 22/2222/22222, and verify offline backups.
Ransomware Groups Disable EDR, Backups and Windows Telemetry Before Encryption
Ransomware operators are increasingly focusing on disabling endpoint detection and response tools, backup systems, and Windows telemetry mechanisms prior to launching encryption. An analysis of the ten ransomware families with the lowest prevention rates in 2026 found that Play achieved only 13 percent of attacks blocked. BlackByte followed with 25 percent blocked and LockBit with 30 percent blocked. BabLock leverages a legitimate uninstaller to remove endpoint protection and terminates processes belonging to antivirus, EDR, backup, and database applications. It then clears the Security and System event logs to hinder incident response. LockBit 5.0 instead interferes with Event Tracing for Windows to reduce visibility for monitoring solutions. Additional families employ process injection, in-memory execution, registry modifications, file masquerading, and living-off-the-land binaries to evade detection.
Chinese Courts Hand Down 16-Year and 32-Year Sentences to Ransomware Operators
Two individuals involved in ransomware operations have received lengthy prison terms in China, with one sentenced to 16 years and the other to 32 years. The cases underscore Beijing's increasing focus on prosecuting ransomware-related crimes. The longer sentence reflects the scale and impact of the criminal activity attributed to the second defendant. Chinese authorities have publicly highlighted these outcomes as part of broader efforts against cyber extortion. The rulings send a clear deterrent message to ransomware actors operating within or targeting Chinese infrastructure.