Business Succession

Hacked: Negotiating with Cybercriminals Instead of Investors!?

The number of hacker attacks on companies is rising every year. What happens if your company is hacked in the middle of the sale process?

Hacker in front of two laptops

Every year, the number of hacker attacks on companies rises. In December 2023, Thyssenkrupp’s materials division was the target of a cyberattack—once again. Recently, Fujitsu and Varta were hit, and the German Chamber of Commerce and Industry (IHK) is warning about phishing. Attacks like these can trigger one of the most severe and sudden restructurings a company can undergo. What happens if your company is attacked by hackers in the middle of the sale process?

An entire industry has now emerged in which hackers go to work every morning to attack companies. You can purchase “cybercrime-as-a-service,” and cybercriminals are organized into specialized teams with commission-based models for their various services. The Federal Office for Information Security warns that this industry releases an average of 250,000 new malware variants—every day.¹ Technically savvy cybercriminals use artificial intelligence to detect and exploit additional vulnerabilities.

So-called ransomware attacks are particularly popular: a ransom is demanded in exchange for the return of the victim’s own data. In companies, such attacks usually come to light when it is already too late: data and documents are encrypted, and in many cases, backups are as well. Unlike a cyberwar attack, the goal is not to drive the company into bankruptcy or render it incapable of operating in the long term; rather, it is a business model designed to extort money.

How does a ransomware cyberattack unfold?

First, initial access is required, which is achieved through methods such as phishing or by exploiting vulnerabilities in various software products. There are virtually no limits to the attackers’ creativity, and every defense measure will eventually be breached. The weakest link is often the human factor, and employees must be made aware of how such attacks can unfold.

Such access opens a backdoor through which malware has already been injected or is downloaded. In some cases, the initial attacks lie dormant and spread after a certain waiting period. Automated tools are often used to move horizontally and vertically through the network and gain access to sensitive data.

Subsequently, files and systems are encrypted, making access impossible and, in most cases, significantly disrupting the company’s business operations. Sensitive data is also often exfiltrated, which could later appear on the dark web.

In such a situation, it is important to proceed calmly. All priorities are focused on the attack, and the sale of the company takes a back seat.

1. Seek and Provide Immediate (Cyber) Assistance
Seek professional help from cybersecurity experts and security service providers.
Isolate infected systems and limit the damage.

2. Risk Assessment
Analyze the current situation and the actual and potential risks.
Assess tangible and intangible damages and their impact on the transaction.

3. Forming a Crisis Response Team
If necessary, seek legal counsel, IT forensic experts, or communications specialists
A cyberattack is an emergency that must be treated as a crisis and mitigated.

4. Open Communication
Communicate with your M&A advisor and potential buyers.
Discuss the situation as the sales process progresses. The process will be put on hold until the situation is resolved.
Communicate openly and transparently during the market approach or in negotiations.

5. Company Sale Process
Pause the M&A sales process.
Take the necessary measures and resume the process once the crisis is over. Then discussions can resume.

What does this mean during the attack?

Company data such as operational data, supplier agreements, customer contracts, personnel files, financial statements, business plans, and forecasts may be inaccessible due to encryption. This creates a challenging situation for day-to-day operations or for providing documents to the data room.

After encryption, the attackers almost always demand a ransom—typically in cryptocurrency—in exchange for providing the decryption keys or agreeing not to publish the stolen data.

In some cases, negotiations may take place to reach an agreement or adjust the ransom amount. To remain operational, the company must make a decision, such as paying the ransom or restoring data from backups—provided these backups have not also been infected by the ransomware.
Cooperation with law enforcement agencies is also recommended.

Once the ransomware has been removed or the ransom has been paid, the company must restore the affected systems. This may involve using decryption tools, restoring data from backups, or taking other measures to secure the affected data. Keep in mind: Paying the ransom does not necessarily guarantee that the data will be decrypted. The company is at the mercy of the criminals in this situation.

Once all traces of the malware have been removed and the systems are operational again, the company can resume its day-to-day business and restart any suspended negotiations.

As mentioned, you should communicate proactively regarding a cyberattack. Losing a prospective buyer due to a lack of transparency is certainly unpleasant. But a subsequent lawsuit over withheld information is far more costly and constitutes negligence. Put the sale on hold; you’ll need to focus entirely on the cyberattack.

How can you protect yourself? After the attack is before the attack

It is possible that further attacks will occur. In principle, every company should review and improve its security measures to prevent future cyberattacks or minimize the likelihood of them occurring. Such a restructuring begins at the latest during the attack phase and has a long-term impact extending beyond the resolution of the incident. Every employee is directly or indirectly affected and must adapt to the new situation. Processes, software, or decision-making procedures will be changed during or after the attack.

The BSI serves as a central information hub for preparation. It recommends implementing security patches and, of course, training employees to recognize phishing attacks. Additionally, further security solutions can be implemented, especially if a company is particularly dependent on its data and IT infrastructure.

There are countermeasures for every phase of an attack that can be implemented or advised upon by an IT security service provider. If you do not have in-house experts, you should seek professional advice.

Conclusion

It is said that sooner or later, every company will become the target of a cyberattack. Restructuring for prevention typically begins no later than the first attack. However, preparation is worthwhile, as cybercriminals increasingly take the path of least resistance and tend to target weaker organizations. While being better prepared than other companies won’t prevent an attack, it does increase the likelihood of being spared.
You don’t have to run faster than the lion—just faster than the others running away from it.

Footnote

1 BSI Bonn Situation Report 2023 www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Lageberichte/Lagebericht2023.html

Share