GUTcert Investigates Security Incident and Possible Data Exposure

Summary
GUTcert has notified the data protection authority and is investigating which individuals and data may have been affected. Customers were first informed on September 14, 2026.
Key points
- GUTcert submitted a preliminary notice to the relevant data protection authority.
- The company is still assessing which individuals and data may have been affected and the associated risks.
- Customers were first notified about the incident and possible data exposure on September 14, 2026.
- GUTcert is reviewing its processing activities and data-protection roles and will provide affected customers with further findings.
- Organizations are advised to assess their own reporting duties under BSIG, NIS2, DORA, and applicable critical-infrastructure rules.
- The article gives no details about the incident's cause or the specific data confirmed to be exposed.
Article Details
- Victim Organization
- GUTcert
- Victim Domain
- gut-cert.de
- Incident Type
- Security incident with possible data leakage; the scope remains under investigation
- Affected Records
- Not disclosed
- Affected Data Size
- Not disclosed
- Operational Impact
- Not disclosed
- Claim Status
- confirmed