Ransomware attack on Crealogix: former CEO describes the nightmare of 2019

A man is standing trial in Zurich, who is alleged to have belonged to a notorious ransomware gang. One of the victims: the Zurich IT firm Crealogix.

Ransomware attack on Crealogix: former CEO describes the nightmare of 2019

Screens frozen, e-mails dead: how Crealogix became a ransomware victim

It is shortly before end of business on 25 July 2019 when Thomas Avedik, then CEO of the Zurich IT company Crealogix, receives a call that turns his life upside down. An employee reports that he can no longer open any files – instead, an extortion message appears on the screen. As the NZZ reports, Avedik initially thinks it is a bad joke. Minutes later, reports start piling up.

"That's when we knew something extraordinary had happened," Avedik says today. For him and a crisis team of around thirty people, this marks the beginning of the most difficult phase of his career – one that will last several months.

Infiltrated via a fake e-mail

Investigators later reconstruct how the criminals broke into Crealogix's network, as emerges from the indictment by the Zurich State Prosecutor. It all begins at the end of May 2019 with a phishing e-mail: an employee clicks on a link, whereupon the malware "Megacortex" is introduced into the company network.

For more than two months, the attackers move undetected through the network, obtain additional access rights and prepare the actual attack. On the afternoon of 25 July 2019, they strike: all servers and the work computers of around one thousand employees at various locations worldwide are encrypted. Screens freeze, files become inaccessible, phones and e-mail systems fail.

Ransom demand of up to 600 Bitcoin

On all affected computers, the perpetrators leave a text message: payment in Bitcoin or the data remains locked. According to the indictment, the attackers demand up to 600 Bitcoin – at that time around 5.5 million Swiss francs. And they explicitly warn: the company should not even attempt to portray itself as small and insignificant. "This shit doesn't work at all," the perpetrators write.

In fact, the criminals had previously introduced their malware into numerous other companies worldwide. In those cases, however, an attack did not occur – presumably because there would have been too little to gain.

Crealogix not the only Swiss victim

The gang, with trails leading to Russia, is said to have carried out 1800 attacks in 71 countries according to Europol. Crealogix is not the only Swiss company to be targeted. Two days before the attack on the IT firm, the same hackers disable Meier Tobler, a trading company specialising in heating and sanitary technology. Several months later, rail vehicle manufacturer Stadler Rail is hit.

A man is now standing trial in Zurich, who is alleged to have been a high-ranking member of this ransomware gang.

"Like marching in the darkness without a torch"

Avedik describes the first days after the attack in forceful terms: "It was as if we had to march over a mountain in the darkness and without a torch. No one knew where it was going. No one could say whether we would really manage it."

Together with internal specialists, external experts and the police, Crealogix quickly establishes a communication line through which all employees are informed of the attack. At the headquarters in Zurich, an improvised control centre is set up. Around thirty people form the crisis team; all other employees are sent on holiday for two weeks. Avedik himself returns home for only a few hours each day.

The goal: to rebuild the systems through painstaking detailed work. The encrypted files cannot simply be restored. Although backups exist, they are one week old. Moreover, millions of lines of code must be checked for any hidden Trojans that could have been used for another attack, as Avedik explains.

Ransomware is nowadays a mass business

At the time of the attack on Crealogix in the summer of 2019, such sophisticated cyberattacks are still comparatively little known. Today they are a mass phenomenon. Criminal groups operate them industrially, some with proven links to the Russian state. The use of artificial intelligence is accelerating this development further.

In the past week alone, 25 reports of hacking attacks were received by the Federal Office for Cybersecurity. According to an analysis by security service Bitdefender, 4641 ransomware group attacks were recorded worldwide in the first half of 2026 – 35 of them affected Swiss companies. Only those cases were recorded in which the cybercriminals publicly claimed responsibility for the attack.

A recently published Deloitte study shows that smaller and medium-sized Swiss companies are lagging behind in cyber defence and the risks are often underestimated.

Source: NZZ

Read this article in the original language