Important Note

Dear Sir or Madam,

We are writing to inform you of a cyberattack on our website that was detected on October 7, 2026. In this notice, we explain the incident, its potential impact on you, and the recommended protective measures.

An attacker gained access to our website https://grc.schleupen.de and posted a fake CAPTCHA there using a counterfeit Cloudflare logo. The intent was to trick visitors into downloading malicious code onto their local computers.

If you followed the instructions of the fake CAPTCHA between 8:00 p.m. on October 5, 2026, and 12:30 p.m. on October 7, 2026, there is a risk that malicious code may have been downloaded to your computer.

In this case, please have your computer checked by your IT department, with the assistance of specialists if necessary.

We do not currently know whether the attacker also had access to the personal data of registered users and prospective customers; this is the subject of further forensic investigations.

The website was immediately taken offline on the day the incident came to light—October 7, 2026, at 12:30 p.m.—and completely rebuilt.

The cyberattack was detected very quickly; security mechanisms were activated immediately, and we took extensive protective measures in collaboration with our IT service provider. In doing so, we are following the guidelines of the Federal Office for Information Security.

Of course, we have informed the data protection authority responsible for us about the incident and filed a report with the police.

We are informing you because you may also have been affected by this attack.

Based on our findings from the investigation of the incident, we have no confirmed evidence to date that your data was exfiltrated. If this were the case, the following data could be affected:

  • Email address
  • First name, last name, company
  • Password (encrypted and unusable by attackers)
  • Content of the contact request or conference bookings

 

Bank details were not collected and therefore could not have been accessed.

In the event of a data exfiltration, there is a possibility that your personal information could be used for fraudulent activities.

Regardless, we recommend that you take the following preventive measures:

1. Change your password: Change your password for online stores, platforms, or other services (Windows login, Facebook, X, etc.) if you have used the same password there.

2. Be on the lookout for phishing attempts: Be cautious of emails or messages asking for personal information or login credentials. Official communications always come from our company email address. Be careful when opening attachments.

Helpful tips are also available on the website of the Federal Office for Information Security (BSI):

https://www.bsi.bund.de/DE/Themen/Verbraucherinnen-und-Verbraucher/Informationen-und-Empfehlungen/Cyber-Sicherheitsempfehlungen/cyber-sicherheitsempfehlungen_node.html

We understand that this incident may cause concern, and we apologize for any inconvenience this may cause you. Your trust is important to us, and we are doing everything we can to protect your data. Our ability to respond quickly is a key aspect of this, and we will further strengthen our commitment to data security and customer protection.

If you have any further questions or need assistance, we are always happy to help. Please do not hesitate to contact our Information Security Officer.

You can reach them at informationssicherheit@schleupen.de

- An automatic translation service was used for this translation. -

Back