SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
█ Ransomware INISSION-POWER-RAN 2026-08-21

Inission Power: Deadlock-Linked Ransomware and Employee Data Leak

"Inission Power Finland Oy and Inission Power Oy, the Finnish arms of Swedish industrial electronics group Inission AB, have confirmed that a server intrusion detected on 22 June 2026 was a ransomware attack, and that…"

Inission Power Finland Oy and Inission Power Oy, the Finnish arms of Swedish industrial electronics group Inission AB, have confirmed that a server intrusion detected on 22 June 2026 was a ransomware attack, and that parts of the affected databases were later found published on the internet. The company's own public notice, issued 20 August 2026 and carried the same day by Nyhetsbyrån Direkt, Placera, EFN, Zonebourse and MarketScreener, states the exposed data may include names, addresses, contact details, Finnish personal identity codes, bank account details, salary records, health information and shareholding data belonging to current and former employees, former shareholders and people closely associated with company directors. No source in this set publishes a record count or a number of affected individuals; the company itself says only that the volume of data is large enough that it has not been able to contact everyone potentially affected. Threat-intel aggregator HookPhish reports that the ransomware group Deadlock listed the victim on 25 July 2026 under its former name, Enedo Power. Inission has not publicly named an actor, and that attribution rests on a single lower-tier source.

What Happened

The confirmed timeline is short and consistent across every source. Inission detected a data breach in its server environment on 22 June 2026. The affected environment was isolated and restored to normal operation the same day, and the company states the incident had no material impact on business operations. The technical investigation subsequently established that the intrusion was a ransomware attack.

The important part is what came after containment. In its public notice, the company says that based on the initial investigation it "had no reason to suspect that personal data or other information had been transferred outside the Company's server environment." That assessment did not hold. Parts of the affected databases were later located online, and after further investigation the company says it cannot rule out that other data covered by the breach has also reached third parties or been published.

Two months separate detection from public notification. HookPhish records a Deadlock leak-site entry for "Enedo Power" dated 25 July 2026, roughly a month after detection and roughly a month before Inission's disclosure. That listing date is a publication timestamp, not a breach date, and the HookPhish record confusingly labels 25 July as both the date of breach and the discovery date, which conflicts with the company's own 22 June detection date. Treat the HookPhish date fields as feed metadata rather than incident facts.

The affected entities carry a heavy legacy-naming burden that matters for anyone tracking this: Inission Power Finland Oy was formerly Enedo Finland Oy and Powernet Oy, and Inission Power Oy was formerly Enedo Oyj, Efore Oyj and Powernet International Oy. The Inission Power brand only arrived in April 2026, weeks before the intrusion. Leak-site listings, breach feeds and victim notices will therefore be scattered across at least four different corporate names.

What Was Taken

No party has published a record count, a file volume, or a headline figure for affected individuals. What the company has published instead is a scope definition, and it is unusually broad in time.

Per the company's notice, the target group for notification includes: persons on the Efore Oyj shareholder register on any of fourteen specified dates between 31 January 2005 and 29 March 2018; persons on the Enedo Oyj shareholder register on any of four dates between 31 December 2021 and 7 October 2022; former employees of the company employed at any point between 2000 and 2024; and persons closely associated with company directors recorded in the insider register at any time between 2007 and 2017, including spouses, dependent children and relatives in the same household.

The data categories, consistently reported across the Swedish, French and German coverage and matching the company's own wording, may include names, contact details, addresses, Finnish personal identity codes (henkilötunnus), bank account details, salary records, health data and shareholding information. That combination is close to a worst case for a single dataset. A Finnish personal identity code paired with a name, address, bank details and date-anchored shareholding records is a ready-made identity theft kit, and health data attracts GDPR Article 9 special-category treatment on top of it.

The company acknowledges the resulting risk directly, warning that disclosure of this personal data may increase the risk of identity theft, phishing, fraud and other misuse. It has notified those individuals it has been able to identify and for whom it holds current contact details, and concedes that the sheer quantity of affected data and the investigation time required have made it impossible to reach everyone directly.

Why It Matters

Three things make this incident worth reading closely rather than filing as routine.

First, same-day operational recovery is not breach containment. Inission isolated and restored the affected server environment within hours and kept operations running normally. By the metric most boards track, uptime, this was a well-handled incident. It still ended with personal identity codes, bank details and health records on the open internet two months later. Modern ransomware crews steal before or alongside encryption precisely so that fast restoration does not remove their leverage. Recovery time objectives measure resilience against encryption; they measure nothing at all against exfiltration.

Second, the company's initial exfiltration assessment was wrong, and it said so. The move from "no reason to suspect data left the environment" to "parts of the databases have been found online, and we cannot rule out more" is the single most instructive detail here. Initial triage on an isolated-and-restored server frequently cannot prove a negative on data theft, particularly when logging and egress telemetry were not built for that question. Organisations that publicly commit to "no evidence of data exfiltration" in week one should assume they may be revising that statement in month two.

Third, decades-old records were still live on a reachable server. Shareholder registers from 2005 and insider-register entries from 2007 have no operational purpose in 2026, yet they were in the blast radius. Finnish and EU retention obligations for some corporate records are genuinely long, but retention obligation is not the same as keeping the data hot, indexed and joinable to bank and salary tables on a production-adjacent host. The dormant data was the payload.

Worth noting on targeting: HookPhish characterises the victim as supplying power systems and LED drivers for critical infrastructure and industrial applications including defence and railway technology. That framing comes from a single OTHER-tier source, and the leak that actually materialised was HR and shareholder data, not product or customer engineering material. There is no evidence in any source of customer or supply chain impact.

The Attack Technique

Initial access vector is unknown. Neither the company's notice nor any of the outlet coverage identifies how the attackers got in, what tooling was used, whether a ransom was demanded or paid, or what was encrypted. No indicators of compromise, no ransomware family details and no dwell-time estimate have been published.

The only actor attribution available is HookPhish's report that the group Deadlock listed Enedo Power on its leak site on 25 July 2026. That is one OTHER-tier aggregator sourcing from public threat-intel feeds, and Inission has not confirmed it. Given that the company independently confirms both a ransomware attack and subsequent online publication of database contents, a leak-site listing in that window is plausible and consistent, but it remains unconfirmed by the victim and should be handled as a single-source claim.

What can be stated with confidence about the technique is only the pattern: double-extortion. Data was taken from a server environment, the environment was hit with ransomware, restoration happened quickly, and the stolen data was published anyway. HookPhish's own generic guidance points at stolen credentials and phishing as the dominant entry points for this class of intrusion, which is accurate as a base rate but is not a finding about this specific case.

What Organizations Should Do

  1. Audit HR, payroll and shareholder-register systems for data you are no longer required to keep hot. Registers going back to 2005 and employment records back to 2000 sitting on a reachable production server turned a contained incident into a multi-decade privacy breach. Enforce retention schedules technically, and move genuinely required long-term records to offline or write-once archival storage that is not joinable to live systems.
  2. Build egress telemetry that can answer the exfiltration question in week one. If your only post-incident evidence is host logs from a server you already restored, you cannot credibly say data did not leave. Deploy network flow monitoring, DLP on outbound paths, and volumetric alerting on database exports, and retain those logs long enough to survive a two-month investigation.
  3. Separate your recovery metrics from your breach metrics in incident reporting. Same-day restoration is a real achievement and should be reported as such, but it should never be presented to executives or regulators as evidence that data was not stolen. Track containment and exfiltration assessment as two independent workstreams with two independent sign-offs.
  4. Write disclosure language that survives revision. Phrase early statements as "our investigation to date has not identified evidence of data transfer" rather than "no data was taken." Inission had to walk back its initial assessment publicly; the wording of the first statement determines how damaging that walk-back is.
  5. Map your own legacy corporate identities before you need them. This victim appears in feeds under Inission Power, Enedo, Efore and Powernet. If your organisation has been renamed, merged or divested, add every historical name and domain to your leak-site and dark-web monitoring queries, or you will miss your own listing.
  6. Treat special-category data as a segmentation boundary. Health records and national identity codes should not share a database, a host, or a credential with salary and banking tables. Where a single system genuinely needs both, encrypt the special-category fields with keys held outside the application host so a server compromise does not yield plaintext.
  7. Pre-plan mass notification for populations you can no longer contact. Inission conceded it cannot reach all affected former employees and long-departed shareholders directly. If your retained data covers people who left twenty years ago, your breach playbook needs a public-notice and registry-based fallback ready in advance, not improvised under regulator pressure.

Sources: Inission Power Confirms Ransomware Attack as Employee, Banking, Sal... | Dataintrång hos Inission Power (tidigare Enedo) Placera.se | Une intrusion informatique détectée chez Inission Power le 22 juin... | Inission Power von Ransomware-Angriff betroffen - Personendaten im... | Data breach at Inission Power - Inission Power | UPPTÄCKTE DATAINTRÅNG 22 JUNI, VAR UTPRESSNINGSATTACK Placera.se | Ransomware Group Deadlock Hits: Enedo Power | Dataintrång hos Inission EFN.se