German firm files for insolvency, blames cybercrims who shut down production for 6 weeks
(www.theregister.com)
ZEGO did not disclose what kind of attack it suffered, whether ransomware was involved, who was behind it, or whether customer or employee data was compromised
GDPR states that if personally identifying information was compromised, the users must be notified. They can't just decide not to publish what happened. It's against the law.
This screams "upper management didn't make security a priority".