Independent business intelligence · Published by Magrofy Inc.New insights every week
Look At BusinessLook At BusinessLook At BusinessBusiness intelligence
Partner

A Cyberattack Just Killed a 37-Year-Old Company

See how one cyberattack can disrupt operations, destroy business continuity, expose weak controls, and threaten the survival of an established company.

By Editorial TeamJuly 21, 2026
A Cyberattack Just Killed a 37-Year-Old Company
MONEY & OPERATIONS

Every board conversation about ransomware is about the ransom — how much, do we pay, are we insured. The ransom is almost never what kills you. Six weeks of darkness is.


ZEGO Textilveredelungszentrum had been finishing textiles in Germany for thirty-seven years. On March 29 it was attacked. Production stopped for close to six weeks. In July the company filed for insolvency, citing significant financial strain.

It joins a very short list of businesses publicly confirmed to have been killed by a cyberattack — a list that until recently was short enough to be treated as anecdote rather than category.

Three months later, Coca-Cola disclosed that unauthorized access to systems at its fairlife subsidiary — including production-related systems — had temporarily suspended US production. Canadian operations were unaffected. Product safety was not compromised. No financial impact figure was given, and none was needed.

Same class of event. Same operational effect. Two entirely different outcomes, and the variable that separated them was not security posture.

What the numbers actually say

Coveware's second-quarter data contains a detail that should change how this gets discussed in boardrooms. The average ransom payment was $1,880,612, up 176 percent on the prior quarter. The median fell 50 percent, to $150,000. The payment rate hit a record low.

The average is being dragged upward by a handful of enormous outlier payments. The typical company facing an extortion demand this year is looking at something closer to $150,000 — an unpleasant number, and for most mid-market firms a survivable one.

Which is precisely why the ransom is a distraction. Most companies could find the money. What almost none of them can find is six weeks of revenue.

ZEGO did not fail because it could not afford a ransom. It failed because a business with thirty-seven years of operating history could not absorb a month and a half of not operating. Coca-Cola absorbed the same event without anyone seriously questioning its continuity, because it has a balance sheet built for shocks and a customer base with nowhere else to go.

The asset nobody puts on the balance sheet

Here is the part that turns an IT incident into a strategic one, and it has nothing to do with technology.

When you cannot ship for six weeks, your customers do not wait. They cannot. They have their own commitments, and the first thing a competent procurement manager does when a supplier goes dark is qualify an alternative. That process — sampling, testing, approving, onboarding — takes weeks, which is exactly the window your outage provides.

And qualification is sticky. Having gone through the cost and effort of approving a second supplier, most buyers keep them. They may give you back some volume. They rarely give back all of it, and they now have permanent leverage on price because they have a demonstrated alternative.

So the revenue does not simply pause and resume. A portion of it transfers, permanently, to whoever was ready. Nothing in a disaster recovery plan measures this, because DR is written by people who think about systems being restored, and the customer relationship does not restore on the same timetable as the ERP.

Visual 1 — What the board asks, and what actually determines survival

The usual board question

The question that decides the outcome

Are we secure? Have we passed our audit?

How many weeks can we be dark and still be a going concern?

Would we pay the ransom?

Does paying actually shorten the outage? Frequently it does not — decryption is slow and often incomplete.

Are we insured?

What is the waiting period on the business interruption cover, and is it longer than our cash runway?

How fast can IT restore systems?

How fast can we ship product with no systems at all — and have we ever tried?

What is our recovery time objective?

At week three, what do our ten largest customers do?

What did the penetration test find?

Which single supplier or system, if unavailable for a month, ends us?

How to read it: The left column is a security conversation and it belongs to the CISO or the IT manager. The right column is a solvency conversation and it belongs to the CEO. Most companies only ever hold the first one.

Why mid-market companies are structurally exposed

This is not about smaller companies being careless. It is about three things that scale differently.

Liquidity. A large company runs on a cash buffer measured in months. A well-run mid-market manufacturer often runs on weeks, by design, because tying up working capital is expensive and the business has never needed a buffer that large.

Substitutability. Coca-Cola's customers cannot switch to a different Coca-Cola. A textile finisher's customers can switch to a different textile finisher, and there are several.

Manual fallback. Older mid-market businesses often assume they could run on paper if they had to — an assumption inherited from a time when they did. That assumption has usually expired without anyone noticing. The machines need the scheduling system. The scheduling system needs the network. Nobody has run the paper version since 2011, and the people who knew how have retired.

The uncomfortable version of this: the companies most likely to be killed by an outage are frequently the ones that modernized enough to be fully dependent on systems but not enough to have redundancy in them. That is a large share of the mid-market.

Five questions worth answering before you need to

  1. What is our maximum tolerable outage, in weeks? Not hours — weeks. Work it from cash, not from technology. If nobody in the business can state this number, that is the finding.

  2. At week three, what happens to our top ten customers? Call the relationship owners and ask them, individually. The answers will not be uniform and the variation is the useful part.

  3. What is the waiting period on our business interruption cover? Many policies do not begin paying for days. Compare that period against the answer to question one.

  4. Can we ship anything at all with no systems? Not in theory. Has anyone tried it, this decade, for a full day?

  5. Which supplier or system, unavailable for a month, ends the company? Most firms find one or two. Very few have ever written them down.

What this changes

Nothing here argues for spending more on security, and that omission is deliberate. Security spending reduces the probability of an incident. It does very little about the duration of one, and duration is the variable that killed ZEGO.

The investments that address duration are unglamorous and mostly not security products: tested restoration from backups that are actually isolated, a documented manual mode with people who have practiced it, a second qualified supplier for anything single-sourced, and a cash or credit facility sized against the outage number rather than against ordinary trading conditions.

And one conversation that costs nothing. Ask your largest customers, in advance, what their tolerance would be. Some will have a contractual answer, some will have a candid one, and a few will tell you they would move immediately — which is worth knowing before it happens rather than during.

A thirty-seven-year-old company with employees, customers and a reputation is now gone, and the sequence that ended it was: attacked in March, dark for six weeks, insolvent by July. There was no dramatic ransom demand at the center of the story. There was just a business that could not operate for long enough, and a set of customers who could not wait for it.

Most boards cannot state how long their own company could be dark. It is the single most useful number in this entire subject, and producing it takes an afternoon.


Sources and method. A LookatBusiness original. ZEGO Textilveredelungszentrum insolvency following a March 29, 2026 attack and a near six-week production outage, as reported by The Register, July 13, 2026. fairlife production suspension per The Coca-Cola Company investor relations, July 16, 2026; the company stated that the full scope and impact were not yet known and gave no financial impact figure. Ransom payment figures — average $1,880,612, up 176 percent quarter on quarter; median down 50 percent to $150,000; payment rate at a record low — from Coveware by Veeam, July 30, 2026, drawn from the firm's own case data. We have cited both the average and the median deliberately: the average alone materially misrepresents what a typical company faces.