Threat actor · all actors
ThyssenKrupp industrial-data intrusion (2016)INS-THYSSENKRUPP-2016 insider
🇩🇪 DE
aka ThyssenKrupp 2016 breach
Last updated:
0attributed CVEs
0ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
ThyssenKrupp publicly confirmed in December 2016 that attackers from south-east Asia had stolen project data from its industrial plants and components divisions; investigation attributed the intrusion to professional espionage. No individual insider was charged; included as a documented European industrial-IP loss.
How we know this
- Data origin
- Curated overlay Insider-threat entry synthesised from public reporting and court filings — not a MITRE-tracked intrusion set.
- Techniques
- No ATT&CK techniques mapped.
- Named victims
- 1 extracted from reporting.
Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty. Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
No techniques attributed.
Co-occurring actors
None.