HomeMalware & ThreatsClop Claims Data Theft From Over 40 Companies

Clop Claims Data Theft From Over 40 Companies

Published on

spot_img

Cybercrime,
Fraud Management & Cybercrime,
Incident & Breach Response

Victims Are Assessing Claims of Stolen Databases, CAD Files, and Backups

Clop Claims Data Theft From Over 40 Companies
Image: Shutterstock

In a notable escalation of cybercrime activities, an influential Russian-speaking extortion group, known as Clop, has claimed responsibility for a substantial data breach affecting over 40 companies. This series of attacks has drawn attention particularly because it includes several high-profile organizations such as the oil giant Shell and the manufacturing powerhouse General Electric (GE).

The Clop group is notorious for its supply-chain attacks and has established a pattern of exploiting unpatched vulnerabilities in widely used software. Most recently, it was implicated in a significant July breach that targeted the product lifecycle management software from PTC. Despite the alarming claims made by Clop, the exact methods employed in this latest wave of attacks remain undisclosed.

Interestingly, General Electric has reportedly been removed from Clop’s dark web leak site, which lists companies that have yet to engage in negotiations for a payoff. While GE’s status is now clarified, several other firms, including health technology manufacturer Philips, fintech company Fiserv, and restaurant payment software provider ToastTab, remain listed. Representatives from these companies have stated that customer data remained unaffected during the Clop intrusion.

Allie Rosenberg, a spokesperson for ToastTab, emphasized that the company detected unauthorized access to a limited set of files. She stressed that, to date, the compromised files consist solely of non-sensitive internal documents. The firm acted swiftly by isolating the affected systems on the same day the breach was detected, thereby containing the situation effectively.

Fiserv, which Clop has claimed to have infiltrated, reported that approximately 874 gigabytes of data, including computer-aided design (CAD) files, were stolen. However, Fiserv affirmed to ISMG that there was no compromise of any customer, bank, transaction, or personal data, based on a comprehensive review conducted to date.

Clop’s statements about the data stolen from Shell suggested that they exfiltrated around 89 gigabytes of sensitive engineering documents, including drawings, photos of Shell’s facilities, scans of facility testing reports, and project plans. A spokesperson for Shell confirmed that they are currently investigating a cyber incident involving unauthorized access to a cloud-based IT service managed by a third-party vendor. Fortunately, the unauthorized access has been blocked and contained, with no operational impact reported. Furthermore, there is currently no evidence to suggest that any sensitive personal data was exposed during this breach.

The vulnerability exploited in the recent PTC attack is tracked as CVE-2026-12569. This flaw allows for remote code execution due to improper deserialization of untrusted data within PTC’s Windchill software, which caters to manufacturers, and its FlexPLM offering aimed at brands and retailers. PTC initially published a patch for the vulnerability on June 18, but subsequent exploitation was detected in the wild shortly thereafter, as noted by the threat intelligence firm ReliaQuest on July 22.

Moreover, the leaked data from three of the targeted companies reportedly includes files identified as “files Windchill,” as seen on the attacker’s leak site. Other compromised data types listed there encompass “CAD – files,” “Soft installers,” “Database,” “Backups,” and “Projects.” This trend underscores the increasing sophistication and boldness of cybercriminal groups such as Clop, who continue to challenge traditional security frameworks by leveraging vulnerabilities in critical software systems.

As victims assess the extent of the damage caused by Clop’s cyber assault, the situation serves as a stark reminder of the vulnerabilities that exist within modern digital infrastructures. Organizations are urged to bolster their cybersecurity measures, stay vigilant, and proactively address any unpatched systems to mitigate the risks associated with such attacks.

Source link

Latest articles

Operation ASTERIX Utilizes Vishing and Fraudulent Crypto Wallet Apps to Steal Seed Phrases

Operation ASTERIX: A Sophisticated Cryptocurrency Fraud Scheme Operation ASTERIX has emerged as a notably intricate...

Zhipu GLM-5.3 AI Model Claims Enhanced Vulnerability Detection

Chinese AI Developer Zhipu Launches GLM-5.3, Competes with American AI Systems in Cybersecurity Last week,...

US FCC Considers Crackdown on Chinese Transceiver Supply Chain

Draft Expansion of Covered List Targets AI Data Center Components in Supply Chain Crackdown In...

HoneyMyte Enhances CoolClient with Windows Kernel Rootkit to Conceal Malware and C2 Connections

HoneyMyte's Escalation in Espionage Tactics: The Upgrade of the CoolClient Backdoor Recently, cybersecurity researchers have...

More like this

Operation ASTERIX Utilizes Vishing and Fraudulent Crypto Wallet Apps to Steal Seed Phrases

Operation ASTERIX: A Sophisticated Cryptocurrency Fraud Scheme Operation ASTERIX has emerged as a notably intricate...

Zhipu GLM-5.3 AI Model Claims Enhanced Vulnerability Detection

Chinese AI Developer Zhipu Launches GLM-5.3, Competes with American AI Systems in Cybersecurity Last week,...

US FCC Considers Crackdown on Chinese Transceiver Supply Chain

Draft Expansion of Covered List Targets AI Data Center Components in Supply Chain Crackdown In...