We were attacked
“Is someone working on the local server?” Monday morning began with an innocent question from a colleague. Then we discovered locked data and a ransom demand. We had been attacked too. Why am I writing about this when companies hide such attacks behind the words “technical difficulties”? Because silence benefits the attackers.
When an attack happens to you, you suddenly see everything else behind the locked data: uncertainty, anger and questions that need answers. After a detailed review of the attack, the experts brought in by the insurer assessed that it was most likely the work of an individual, a “lone wolf”, as they put it. Just as in every other sector and industry, there are malicious people in IT and software development, without a shred of empathy, who want to make money quickly through criminal acts. And this is becoming increasingly common.
My first reaction? F***! Numerous thoughts raced through my mind at once about what to do in that moment. Thanks to my colleagues and their composure, we acted quickly. We immediately notified all the relevant authorities, took a breath and began a full analysis and recovery.
I admit that I spent quite some time wondering whether to write about this at all. When I started discussing it with others, including the insurer, they told me how common it was. Yet companies are afraid to admit it and speak about it. Many well-known companies in Slovenia have experienced an attack. Some simply announced: “We had technical difficulties.” Hmm, yes, they did. So did we. Quite serious technical difficulties.

Why keep quiet? Because you are afraid your clients might stop trusting you. But when you start talking openly, others find the courage to admit it too. That is how I discovered that this happens far more often than I could have imagined. This is precisely why we need to talk about attacks and take care of security alongside digitalisation. Digital tools really do make our work easier, but with every new system we become more dependent on its secure operation. If we neglect protection, a single attack can bring work to a halt and put the data we rely on every day at risk.
So how did it happen to us? They gained access to our internal/local servers through a security vulnerability in software we were using. The production servers hosting all our clients are at other locations and remained untouched. The affected servers were used for testing and internal work.
In reality, we were lucky in an unlucky situation. Only when something like this happens to you do you realise how vulnerable you are. How everything you hear about can happen to you too. The attacker simply locked the entire server and left a message stating how much money he wanted to unlock it again. We immediately shut down and isolated the server, and we had backups in place for everything. I must admit that, for the first time, I was very glad we pay a fairly high premium to an insurer that covers all the costs. And not just that: above all, the responsiveness and commitment mattered. Advice, assistance, forensics...
We are not quite finished yet, but about a month has passed, while the deadline set in the ransom threat was two days. After communicating with us, the attacker has stopped responding, and the insurer has also helped us with various measures. These include setting up enhanced monitoring for any publication of our data on the dark web over a three-month period. As well as locking data, attackers may threaten to publish it if they do not receive a ransom. Monitoring would allow us to detect any publication as quickly as possible and respond. The fact that the attacker is no longer responding does not mean the risk of publication has passed.
Digital is convenient, but also vulnerable
Just a decade ago, binders, stamps and fax machines were a standard part of every office. Today, we send invoices by email, store documents in the cloud, meet clients on video calls, and colleagues access systems from home or on their phones. Digitalisation has saved us enormous amounts of time and paper and enabled ways of working we could not have imagined a few years ago.
But it has another side too. Every new system, every connection and every user account is also a new door that someone may try to open.
The numbers are rising

Slovenia’s cybersecurity incident response centres see this clearly in their data. In the first half of 2025, SI-CERT and SIGOV-CERT together handled 2,786 security events and incidents, approximately 15% more than in the second half of 2024. Simple phishing cases are not included in these figures at all; there were another 3,129 of those during the same period. There were slightly fewer incidents in the second half of the year, but mainly because the counting methodology changed, not because the attackers were taking a break.
The damage is considerable too. As early as 2023, 51 cases of so-called BEC fraud, in which an attacker infiltrates business communications, were recorded, causing Slovenian companies losses of €7.8 million.
Where it most often starts
It rarely looks like a film scene with hackers in hoodies. Most often, it begins with something quite ordinary:
- A fake email, which looks like a notification from a bank, supplier or delivery service and asks the recipient to click a link or enter a password.
- A stolen or weak password, which someone uses in several places.
- Unpatched software, meaning systems that have not been updated for a long time.
- Poorly secured remote access, which was set up “temporarily” and then left in place.
Ransomware is particularly dangerous. It encrypts data and demands a ransom for the key. Increasingly, attackers also steal the data before encrypting it and threaten to publish it. At that point, it is no longer just about downtime, but also about client trust and obligations concerning personal data protection.
What we can do
There is no such thing as complete security, but we can make the attackers’ job much harder. Most measures are not expensive, but they require consistency:
- Two-factor authentication (2FA) wherever it is available, especially for email, cloud services and remote access.
- Regular updates to operating systems, software and servers.
- Backups, stored separately from the main system, and occasional checks to confirm they can actually be restored.
- A healthy degree of scepticism towards unexpected messages, urgent payment requests and changes to bank account details. One phone call to verify the information can often prevent major losses.
- An access review: who has access to what, and whether they still need it.

If an incident does occur, a quick and calm response is essential. Infected devices should be disconnected from the network, those responsible notified, and the incident reported to the national centre SI-CERT, which also helps companies that are not subject to statutory requirements.
Digitalisation is not the enemy
None of this is a reason to go back to binders. Digital tools remain one of the greatest advantages of modern business. Just as we lock the office at the end of the day, we must also take care of our digital locks. Security is not a one-off project, but a habit, much like fastening a seat belt. Once we adopt it, we barely notice it anymore.
This experience certainly taught us a lesson, and we have taken many additional measures for the future and for secure operations. I certainly recommend that you do the same.
Jurij Triller
