OMS shows how a cyberattack can become a working-capital shock

OMS shows how a cyberattack can become a working-capital shock

Slovak lighting maker OMS is winding down after a failed restructuring, more than €6 million in reported debts and a collapse from roughly 1,000 employees at its peak to five. Its board says an October 2025 cyberattack hit HR and ERP systems and cost the company key data, but did not cause the crisis. The sharper lesson is how digital disruption compounds financial weakness.

OMS did not collapse because hackers flipped a switch. By August 2026, the Slovak lighting manufacturer was heading out of a failed restructuring and toward an asset sell-off, with more than €6 million reportedly owed to the state and commercial partners and just five employees left. Yet the detail that turns this from another insolvency story into a warning for industrial companies came from board member Daniel Levársky: an October 2025 cyberattack hit the company’s personnel and enterprise resource planning systems and caused the loss of some key data. He said the attack was not the cause of the company’s situation, but materially contributed to its development.

That distinction matters. The cyberattack was an accelerant, not an origin story. OMS had already shrunk dramatically from its peak, had recorded a €935,569 loss in 2024, and was struggling to finance operations. The case therefore exposes a less theatrical but more useful cyber risk: when a manufacturer has little cash, weak access to credit and delayed projects, damaged operational data can turn recovery time into a liquidity requirement it may be unable to fund. The real security boundary is not the server room. It is the company’s capacity to keep converting orders into cash while systems are impaired.

The crisis was financial before it was digital

OMS’s filed accounts make the chronology harder to sensationalise. In 2023 the company reported net turnover of €5.86 million and a small after-tax profit of €272,722. The same filing shows €11.12 million of proceeds from sales of long-term assets and material that year, a figure that makes the small net profit insufficient on its own to demonstrate a recovery in recurring product sales. In 2024, net turnover fell to €2.94 million and the company lost €935,569. Those figures pre-date the October 2025 cyberattack and establish that financial weakness was already real. The filing also shows a negative financial result of €330,937 in 2024, after a much larger negative financial result in 2023, another sign that operating recovery had to coexist with financing pressure.

The deterioration continued in the 2025 accounts. OMS reported net turnover of €2.75 million, total operating revenue of €3.92 million and operating costs of €5.56 million. Its after-tax loss widened to €1.76 million. Personnel costs fell from €2.09 million in 2024 to €1.60 million in 2025, consistent with the reported staff reductions while the business still failed to cover its cost base. These numbers cannot isolate the damage caused by the cyberattack, because they cover the full calendar year, but they show the narrow financial runway into which the incident landed.

Levársky’s explanation adds the missing operational link. He told Forbes and was quoted in subsequent Slovak reporting as saying OMS still had customers and orders but lacked the money to finance them after losing access to bank funding. In October 2025, Forbes reported his claim that the company had about 40 active customers, projects worth roughly €500,000 a month and delayed work worth about €7.6 million that management hoped to complete in 2026 and 2027. Those were management claims, not audited forecasts, but they point to the central contradiction: demand can exist while a company still runs out of the cash needed to serve it. The claimed €7.6 million of delayed work was also almost three times OMS’s entire 2025 net turnover, a calculation that illustrates the scale of execution required relative to the business it had become.

Thirty years of scale left less room for recovery

The scale of the fall is stark because OMS had once been a substantial exporter and manufacturer. Vladimír Levársky founded the business in 1995, moving from lighting trade into development and production. Forbes reports that OMS was an early adopter of LED technology and generated more than €80 million in revenue in 2013. Other Slovak reporting puts peak employment at more than 1,000 people. By August 2026, only five employees remained. This was not a young company losing a speculative bet; it was an established industrial organisation losing the capacity to keep operating.

The decline also predates the latest financing crunch. Hospodárske noviny reports cumulative losses of about €22 million between 2016 and 2022, attributing the period to problems managing rapid expansion and internal processes. In 2017, Ivan Kmotrík’s Grafobal Group bought a 70 percent stake; in May 2024 it transferred that stake back to the founder. That history matters because repeated ownership and restructuring efforts can reduce the pool of easy remedies. Cost cutting, asset sales and new capital may buy time, but each can leave fewer buffers if operating performance does not recover. That matters in a cyber crisis because a company that has already exhausted obvious restructuring levers has fewer ways to fund emergency specialists, replacement infrastructure or the extra labour required for manual recovery.

There was still a strategic rescue story being told in 2025. OMS announced a partnership with Danish lighting company Teamtronic in July, presenting the tie-up as a way to combine Scandinavian market access with Slovak production and research capacity. Teamtronic separately described itself as becoming a co-owner and said the investment supported its European growth and supply-chain strategy. Those announcements are useful as evidence of the partners’ intentions, not proof that the combination was financially sufficient. Within months, optimism about capacity and European production was colliding with creditor protection and a cyber incident.

The attack landed inside the systems that coordinate production

The public description of the incident is limited but unusually consequential. Regióny.sk, citing Levársky, reports that the October 2025 cyberattack affected OMS’s personnel system and its ERP system and caused the loss of some key data. The available sources do not identify the attacker, entry vector, malware family, ransom demand, exact outage duration, quantity of lost data or whether information was exfiltrated. Calling the OMS incident ransomware would therefore go beyond the evidence. What is verified is the impact on two systems that sit close to the coordination of people and operations.

ERP is not merely accounting software. SAP describes enterprise resource planning as an integrated system spanning functions such as finance, HR, manufacturing, supply chain, sales and procurement, built around a unified view of business activity. In a manufacturer, that integration is precisely why an ERP disruption can be expensive: the affected data may be needed to establish what was ordered, what materials are available, what must be purchased, what can be produced, what has shipped and what can be invoiced. The exact modules OMS used are not public, so the mechanism should be understood as a risk pathway, not a reconstruction of its incident.

That pathway becomes more dangerous when the company is already operating with fewer staff. At the start of 2026, Slovak reporting says OMS had about 27 employees; by August it had five. A much smaller workforce has less spare capacity for manual workarounds, data reconciliation, customer communication and system recovery, although the public evidence does not show which roles remained or how OMS allocated recovery work. The relevant point is operational: restoring data is one task; rebuilding confidence in the accuracy and completeness of the records needed to execute projects is another. A database can be technically online while managers are still checking whether its contents are complete enough to make purchasing, production and billing decisions safely.

Working capital turned downtime into a financing problem

A manufacturer can be commercially busy and financially trapped at the same time. Orders usually create obligations before they create cash: materials may have to be bought, employees and suppliers paid, products built and delivered, and customer acceptance secured before the invoice turns into usable cash. OMS’s management explicitly linked the company’s failure to the absence of money for financing orders despite continuing demand. That makes working capital the bridge between the cyber event and the insolvency story.

Consider what system disruption does to that bridge. If reliable information about inventory, procurement, production status, customer orders or billing becomes unavailable or untrusted, a company can face slower purchasing decisions, duplicated checks, delayed production, disputed deliveries or postponed invoicing. Those are general consequences of losing access to integrated operational records, not claims about every effect at OMS. But when a company cannot draw fresh bank funding, even a temporary extension of the cash-conversion cycle can become acute. Recovery time has a cash cost, because payroll, energy, rent, suppliers and remediation do not wait for the data environment to become normal.

The restructuring timeline shows how little room there was for error. A court record reproduced from the Slovak insolvency register says proceedings in case 23R/4/2025 began on 4 December 2025 and restructuring was permitted by a 29 December order that became effective on 30 December. In April 2026, the creditors’ committee extended the deadline for the final restructuring plan. By August, Forbes and HN reported that management had told creditors the restructuring could not be completed and that assets would be sold. A recovery plan that depends on completing delayed projects is exceptionally sensitive to anything that lengthens execution or absorbs scarce cash.

ERP data is operational memory, not back-office clutter

The OMS case gives “protect your data” a more precise meaning. Security discussions often focus on confidentiality: preventing outsiders from reading sensitive information. For a distressed manufacturer, availability and integrity can be just as existential. Data must be accessible when needed, and the company must be able to trust that records have not been lost or altered. The distinction is practical: a secret but unavailable production record is useless, while an available record whose accuracy is doubtful can create its own operational risk. NIS2, the European Union’s cybersecurity directive for entities within its scope, treats those dimensions as part of risk management and explicitly includes business continuity, backup management, disaster recovery and crisis management among required measures.

European threat data explains why manufacturing deserves that attention. ENISA’s 2025 Threat Landscape analysed 4,875 incidents from July 2024 through June 2025. Its manufacturing-sector analysis identified cybercrime as the dominant threat-actor category and described ransomware incidents that caused prolonged business-continuity disruption at EU manufacturers. That does not tell us what happened inside OMS, and it should not be used to fill gaps in the incident record. It does show that operational interruption at manufacturers is a documented European risk, not a hypothetical boardroom exercise.

Slovakia’s own National Security Authority reached a similarly sober conclusion in its 2025 cybersecurity report. It said incident reports and statistics showed growth in both the number and seriousness of incidents and expected the trend to continue into 2026, with AI increasing the automation, scale and effectiveness of attacks. The useful business implication is not to assume every company will be breached. It is to recognise that restoration capacity has to be designed before a crisis, because the worst time to discover that backups, process documentation or recovery ownership are inadequate is when credit is already tight.

Creditors and workers absorb different versions of the same failure

By the time restructuring fails, cyber risk has stopped being an IT department’s private problem. Forbes reported more than €6 million owed to the state and commercial partners. Slovakia’s Social Insurance Agency currently lists OMS with €548,851.64 in debt; the agency cautions that its debtor list is informational and says it is updated four times a month. The exact creditor recovery will depend on the insolvency process and asset realisations, neither of which the public sources reviewed here establish. What is clear is that the costs of failure have moved outside the company. Unpaid claims turn internal operating delays into cash-flow uncertainty for suppliers and public institutions, while an asset sale shifts attention from future orders to the value that can actually be recovered. The reviewed sources do not yet establish those recovery outcomes for OMS.

Employees experience the same collapse in a different unit. The workforce had fallen from more than 1,000 at its peak to around 100 after years of restructuring, according to Slovak reporting, then to roughly 27 as 2026 began and five by August. Those figures describe a long contraction rather than a single post-attack layoff. It would be wrong to attribute hundreds of lost jobs to the October incident. The defensible conclusion is narrower: the attack hit an organisation whose human redundancy had already been stripped back.

Suppliers and customers carry another exposure. In October 2025, management said restructuring was intended not only to save OMS but also to protect suppliers, employees and partners, while completing delayed projects. If the company now sells assets instead, those stakeholders must deal with unfinished commitments, claims and replacement sourcing according to their individual contracts and the insolvency process. Public reporting does not identify the status of each project, so broad claims about customer losses would be speculative. The institutional lesson is that a company’s cyber resilience can become part of counterparties’ credit and continuity risk, especially when that company is already financially weak.

The evidence does not support blaming hackers alone

There is an obvious temptation to turn OMS into a morality tale about one cyberattack destroying a successful factory. The evidence rejects that framing. The company was already far below its historic scale, recorded a sizeable 2024 loss, had a history of accumulated losses, had changed ownership structure, was seeking creditor protection in 2025 and, by management’s own account, lacked normal bank financing. Those are not side notes; they are the preconditions that made any new shock harder to absorb.

The strongest attribution comes from Levársky himself, and it is careful: the attack did not cause the current situation but contributed substantially to its development. Public evidence does not quantify that contribution. We do not know how many production days were lost, how much revenue was delayed, how much remediation cost, whether data could be reconstructed, or what cash would have been available without the incident. No reliable public basis exists for assigning a percentage of the collapse to the cyberattack.

There is also a counterfactual problem. A well-capitalised company can suffer a serious cyber incident and survive; a distressed company can fail without one. OMS sits between those cases: documented financial weakness plus a documented operational-data shock. The thesis therefore rests on interaction rather than monocausality. Cybersecurity did not replace finance as the decisive business constraint. It appears to have made a constrained system worse. That distinction matters for executives because it changes the remedy. Buying another security product cannot repair a broken balance sheet, while raising capital does not make operational data recoverable. Resilience requires both financial slack and tested technical recovery. That is also why causal precision matters: misdiagnosing a combined finance-and-operations failure as a pure security failure would direct money toward only one half of the vulnerability.

Boards need to price recovery capacity like liquidity

For boards and owners, the most useful question is not whether they can prevent every attack. They cannot establish zero risk. The better question is how much cash and operational capacity the business needs if a critical system becomes unavailable or untrustworthy for days or weeks. That means identifying which systems gate revenue, purchasing, production, payroll and regulatory obligations; deciding how much data loss the business can tolerate; and testing whether clean restoration can happen within the period the business can finance. OMS does not disclose those metrics, so this is a decision framework drawn from the risk mechanism, not a claim about its controls. The board-level test is deliberately financial: if restoration takes twice as long as planned, leaders should know which payments, customer commitments and production steps become impossible first.

Regulation is moving in the same direction. NIS2 requires essential and important entities within its scope to use risk-management measures that include incident handling, business continuity, backup management and disaster recovery. Slovakia’s Cybersecurity Act provides the national legal framework, and an NBÚ decree effective from September 2025 specifies security-measure requirements under that framework. These rules should not be read as proof that OMS was within scope or non-compliant; the public material reviewed here does not establish either point. They do, however, show that continuity and recovery are now treated as governance obligations for covered organisations, not optional technical housekeeping.

The practical controls are less glamorous than threat intelligence. Slovakia’s SK-CERT used its 2025 ransomware workshop to teach network segmentation, vulnerability visibility, monitoring and backup approaches including immutable 3-2-1 backups. A board does not need to prescribe tooling, but it should demand evidence that restore procedures work, that backup copies cannot all be modified from the same compromised environment, and that manual fallbacks are documented for the handful of processes that keep cash moving. The decision standard is tested recovery, not the existence of a backup policy.

OMS leaves industrial SMEs with a conditional warning

OMS is an extreme case, but the mechanism is relevant far beyond lighting. A smaller industrial company often depends on a concentrated set of systems, specialised staff, lenders and suppliers. If financial headroom is abundant, a cyber incident can be treated as an expensive interruption. If headroom is thin, the same interruption competes directly with materials, wages and creditor payments. Cyber resilience then becomes a form of liquidity protection, because the speed and reliability of recovery influence how long the company must finance disrupted operations. This is analysis based on the OMS record and the documented role of ERP and business-continuity controls, not a claim that every cyber incident creates insolvency. The relevant exposure is asymmetric: companies with abundant liquidity can buy time, while companies already rationing cash may have to choose which recovery, production or creditor demands to fund first.

The OMS evidence supports three conditions for that warning. First, the company must be financially constrained; OMS’s accounts and management statements show that clearly. Second, the affected systems must matter to operations; the reported impact on ERP and personnel systems meets that threshold, even though the exact damage remains undisclosed. Third, recovery must consume time or resources that the company cannot easily replace. Levársky’s statement that the attack materially worsened the situation supports that link, but the absence of detailed incident data prevents stronger causation. The uncertainty belongs in the conclusion, not hidden in a footnote.

The thesis would weaken if later evidence showed that OMS restored its systems quickly with negligible operational cost, or that the lost data had no meaningful role in delayed orders. It would strengthen if insolvency records, forensic findings or management disclosures documented extended outages, reconstruction costs or revenue delays tied to the incident. Until then, the most defensible judgment is also the most useful: hackers did not single-handedly end OMS. They hit a company whose financial and organisational buffers were already dangerously thin, and that made damaged data more expensive than a healthy balance sheet might have allowed.

Questions the OMS collapse raises for businesses

Did a cyberattack cause OMS Lighting to collapse?

No public evidence supports that simple claim. OMS board member Daniel Levársky said the October 2025 cyberattack was not the cause of the company’s situation but contributed substantially to its development. Filed accounts and reporting show serious financial weakness before and around the incident.

What happened to OMS Lighting in Slovakia?

OMS failed to complete its restructuring. By August 2026, Forbes and Hospodárske noviny reported that the company would wind down through asset sales, with more than €6 million in reported debts and only five employees remaining.

When did the OMS cyberattack happen?

The public reporting reviewed for this article places the cyberattack in October 2025. No reliable public source reviewed here gives a more precise attack date.

Which OMS systems were affected?

Reporting citing Daniel Levársky says the attack affected OMS’s personnel and ERP systems and resulted in the loss of some key data. The public record does not specify the affected ERP modules or the exact volume of data lost.

How much debt does OMS reportedly owe?

Forbes reported total debts of more than €6 million to the state and business partners. The Social Insurance Agency’s current informational debtor list separately shows €548,851.64 owed by OMS.

How many employees does OMS have now?

Slovak reporting in August 2026 says five employees remain. The same reporting says OMS had more than 1,000 employees at its peak, showing that most of the workforce decline occurred across a much longer restructuring and contraction.

Did OMS still have customers and orders during the crisis?

According to management, yes. In October 2025 Daniel Levársky told Forbes that OMS had about 40 active customers and projects worth roughly €500,000 per month. Those figures were company claims and should not be treated as independently audited order-book data.

Was OMS in bankruptcy or restructuring?

Court records show restructuring proceedings in case 23R/4/2025 began in December 2025 and restructuring was permitted at the end of that month. By August 2026, current Slovak reporting said the restructuring had failed and the company was moving to bankruptcy and asset disposal.

What should manufacturers learn from the OMS case?

The evidence supports a conditional lesson: when cash and credit are tight, disruption to operational systems can become a financing problem. Manufacturers should treat recoverable data, tested backups, continuity procedures and restoration time as business-resilience controls, while recognising that cybersecurity cannot substitute for a viable balance sheet.

Author:
Jan Bielik
CEO & Founder of Webiano Digital & Marketing Agency

OMS shows how a cyberattack can become a working-capital shock
OMS shows how a cyberattack can become a working-capital shock

This article is an original analysis supported by the sources cited below

OMS, a.s. individual financial statements for 2025

Slovakia’s Ministry of Finance register supplied OMS’s 2025 turnover, operating revenue, costs and after-tax loss, including the comparative 2024 figures.

OMS, a.s. individual financial statements for 2024

The official 2024 filing established the pre-cyberattack loss, 2023 comparison and the large 2023 proceeds from sales of long-term assets and material.

Zoznam dlžníkov

Slovakia’s Social Insurance Agency provided the current informational debt listing for OMS and explained how frequently the list is updated.

Obchodný vestník SR record for case 23R/4/2025 published 9 March 2026

This reproduced insolvency-register court record established the December 2025 start of the proceeding and the court’s permission for OMS to enter restructuring.

Obchodný vestník SR record for case 23R/4/2025 published 28 April 2026

This record documented the creditors’ committee action extending the deadline for submission of the final restructuring plan.

OMS nezachránil ani jeden z najbohatších Slovákov, ani Dáni. Senická firma už zamestnáva len päť ľudí

Forbes supplied current reporting on the failed restructuring, asset sell-off, reported debt above €6 million, remaining workforce and OMS’s historical scale.

Senický výrobca svietidiel žiada o odpustenie dlhov. Firmu zachraňuje aj investor z Dánska

Forbes documented management’s October 2025 account of creditor protection, active customers, project flow and delayed work the company hoped to finish.

Od miliónových tržieb k piatim posledným zamestnancom. Známy výrobca svietidiel definitívne končí

Hospodárske noviny provided independent context on OMS’s long decline, ownership changes, accumulated losses and management’s financing explanation.

Jedna z TOP firiem Slovenska končí: Mala 1000 zamestnancov. Majiteľ prehovoril, čo je za tým

Regióny.sk supplied the published account of the October 2025 cyberattack, the affected HR and ERP systems, lost key data and Levársky’s causation qualification.

OMS Strengthens Its Innovation Potential and Footprint in Scandinavia Through Strategic Partnership With Teamtronic

OMS’s own announcement documented how the company presented the July 2025 Teamtronic partnership and its intended industrial and market rationale.

Teamtronic strengthens its European position with strategic co-ownership in Slovakian OMS

Teamtronic’s announcement confirmed its co-ownership framing and the strategic objectives it attached to the OMS investment.

ENISA Threat Landscape 2025

ENISA supplied the EU-wide incident dataset and manufacturing-sector context used to distinguish general industrial cyber risk from the unverified specifics of the OMS attack.

Správa o kybernetickej bezpečnosti v Slovenskej republike v roku 2025

Slovakia’s National Security Authority provided national evidence on the rising number and seriousness of reported cyber incidents and its 2026 risk outlook.

Konferencia Kyber2025 – Čo sa deje a čo nás čaká?

SK-CERT’s official programme documented practical emphasis on ransomware response, segmentation, monitoring and immutable 3-2-1 backup approaches.

Directive (EU) 2022/2555

The NIS2 Directive supplied the EU legal benchmark for cybersecurity risk management, including incident handling, business continuity, backup management and disaster recovery for entities within scope.

69/2018 Z. z. Zákon o kybernetickej bezpečnosti

Slov-Lex provided the current Slovak statutory framework for cybersecurity obligations referenced in the governance section.

227/2025 Z. z. Vyhláška Národného bezpečnostného úradu o bezpečnostných opatreniach

Slov-Lex provided the 2025 NBÚ decree specifying cybersecurity security-measure requirements under Slovakia’s framework.

What is ERP? The Essential Guide

SAP’s ERP guide was used only to establish the standard functions integrated by enterprise resource planning systems and the operational mechanism discussed in the analysis.

Citing this article? Brief excerpts are welcome. Please credit Webiano.digital, name the author where stated, and include a link to https://webiano.digital and to this original article. Full or substantial republication requires prior written permission. Read our Copyright and Content Use Policy.

This article was prepared with the assistance of artificial intelligence tools. The content underwent expert human review, and Webiano Digital & Marketing Agency assumes editorial responsibility for its final version and publication.