
Thyssenkrupp Marine Systems Ransomware: 1TB Data Exfiltrated by The Gentlemen (June 2024)
Thyssenkrupp Marine Systems: What Happened
On June 2024, the cybercrime group known as The Gentlemen claimed responsibility for a ransomware attack targeting Thyssenkrupp Marine Systems, a prominent German naval defense contractor, and its subsidiary Atlas Elektronik. The attackers successfully exfiltrated over 1TB of data from the organization. Thyssenkrupp confirmed the compromise, specifying that the breach occurred within an isolated North American business unit. The company stated that, due to the containment of the affected environment, no classified data was accessed or exfiltrated during the incident.
Attack Vector & Technical Detail
While specific vulnerabilities (CVEs) exploited in this incident have not been disclosed, the attack aligns with MITRE ATT&CK tactics TA0011 (Command and Control) and TA0040 (Impact), indicating the adversaries established persistent access and executed disruptive actions. The absence of public indicators of compromise (IOCs) suggests the group may have used custom tooling or living-off-the-land techniques to evade detection. The Gentlemen’s operational approach, as evidenced by the scale of data exfiltration and subsequent extortion attempts, is consistent with advanced ransomware campaigns targeting critical infrastructure and defense sectors. The group publicized their claims via the PrinzEugen leak site (Tor), further pressuring the victim organizations.
Confirmed Impact
The breach resulted in the unauthorized exfiltration of more than 1TB of internal data from Thyssenkrupp Marine Systems and Atlas Elektronik. The affected systems were part of an isolated North American unit, which limited the exposure of sensitive and classified information. Nevertheless, the incident poses significant operational and reputational risks, especially given the organizations’ roles in European naval defense supply chains. Regulatory scrutiny is likely, particularly concerning data protection and incident disclosure requirements in both European and North American jurisdictions. The public association with a ransomware event may also impact stakeholder trust and contractual obligations with government clients.
What This Means for Your Organization
This incident underscores the persistent threat ransomware groups pose to defense contractors and critical infrastructure providers. The use of isolated environments at Thyssenkrupp Marine Systems limited the scope of the breach, highlighting the importance of robust network segmentation and containment strategies. Organizations should review their segmentation controls, monitor for lateral movement, and ensure rapid detection of anomalous data transfers. Proactive threat hunting and regular tabletop exercises can further strengthen preparedness against similar multi-stage ransomware campaigns.
Detection & Response
- Immediate: Isolate affected network segments and initiate incident response protocols to contain potential lateral movement.
- Hunt: Monitor for behaviors consistent with MITRE Tactics TA0011 (Command and Control) and TA0040 (Impact), including unusual outbound connections and large-scale data transfers.
- Patch: N/A (no CVEs disclosed in this incident).
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

