Cl0p hackers claim data theft from Shell, Philips, GE | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Cl0p hackers claim data theft from Shell, Philips, GE

A hacking group has claimed it stole large volumes of internal data from close to 50 companies worldwide in a single coordinated campaign, using one software vulnerability to hit dozens of unrelated targets at once.

The group, known as Cl0p, listed Philips, Shell, Fiserv and GE among its victims in a posting on its website.

Philips confirmed it had been targeted, saying it identified and contained an attempted compromise of a specific enterprise server tied to internal data, with no impact on customer environments. Shell said it was aware of a “possible incident” and is investigating with its security teams, confirming an earlier report from Dutch outlet BNR.

Fiserv said its review so far found no evidence that customer, banking, transaction or personal data Fiserv reported that its review so far found no evidence of compromised customer, banking, transaction, or personal data..

GE stated that it has invoked its cybersecurity response processes to investigate the allegation. It was not possible for Reuters to independently verify the details of the alleged data breach, and no response was received from Cl0p on the matter.

The Ransom-ISAC industry body warned that Clop was taking advantage of the vulnerability in PTC Windchill and FlexPLM, engineering and manufacturing solutions widely used by many businesses.

Brandon Parsons, threat intelligence manager at Ascent Solutions, who was behind the warning, added that some firms had received extortion notices from Cl0p as early as July 19 or 20.

According to Parsons, the gang are “professional data extortionists” who use a single unpatched vulnerability in order to go after companies and not individual companies themselves.

PTC, which is based in Boston, has been issuing security advisories since June 18 to fix the flaw through a patch.

Reports tied to the same disclosure indicate the hackers claim to have taken roughly 89 gigabytes of data from Shell, including engineering drawings and facility inspection reports, and around 13.5 gigabytes from Philips, including technical schematics. Cl0p has not yet released sample files to support those claims.





Click Here For The Original Source.

--------------------------------------------------------

..........

.

.