From an external perspective, everything is now running as usual. The company confirms in a press release that all websites and customer portals for placing orders are now accessible and functioning normally again.
The return to normal has been gradual. On September 8th, the company announced that the order flow had been restarted internally, allowing them to receive and send orders manually via telephone and email while the websites were secured.
Our highest priority is to minimize the impact on our customers, Dustin stated when the incident was first communicated externally.
The IT forensic investigation continues in parallel with the system restarts. The investigation is being conducted in collaboration with external experts in cybersecurity and forensics, focusing on the internal support and administration systems that were affected by the intrusion. The goal is to determine exactly what data has been affected. The incident has been reported to the Police and the Swedish Data Protection Authority.
Customers were informed early on that data may have been exposed.
Currently, we have no information as to whether and which personal data has been compromised, the company told its customers shortly after the attack was discovered.
The company has emphasized in its communication that it will inform affected parties directly if specific organizational or customer data is actually found to have been compromised. In the emails sent to customers, the company also apologized for the incident.
We sincerely apologize for the concerns and problems this situation causes you, Dustin wrote in a customer email.
The e-commerce company’s focus is now said to be on supporting customers and partners in all of the company’s markets, while completing the remaining restoration and remediation work in the underlying IT environment.