Russia-linked hackers claim data theft from nearly 50 global companies
Hackers exploited vulnerabilities in software (photo: Getty Images)
The Russia-linked hacker group Cl0p claimed to have stolen large volumes of data from nearly 50 companies worldwide, including Philips, Shell, Fiserv and GE, according to Reuters.
Company statements
Philips confirmed an attempted cyberattack. The company said it detected and contained an attempt to compromise a separate corporate server associated with internal data. According to the company, customer environments were not affected.
Shell also reported a possible cyber incident. A company representative said cybersecurity specialists and external experts are investigating the situation.
Fiserv said it was aware of the hackers' claims but had so far found no signs that customer data, banking and payment information, or personal data had been compromised. According to the company, its operating environment was also unaffected.
GE has not yet commented on the situation.
Reuters was unable to independently verify Cl0p's claims regarding exactly what data may have been stolen or the volume involved. The hackers also did not respond to the agency's request.
How the hackers operated
According to Reuters, Cl0p may have exploited vulnerabilities in PTC Windchill and FlexPLM software, which is used in design and manufacturing processes.
The industry group Ransom-ISAC warned about the exploitation of these vulnerabilities as early as July 22. PTC also issued a security advisory and urged customers to install the relevant updates.
Cyber threat analyst Brandon Parsons, who authored the Ransom-ISAC warning, said some companies began receiving messages from Cl0p on July 19 or 20.
According to him, the group focuses not on specific companies but on vulnerabilities in widely used software. Parsons described Cl0p as "professional data extortionists."
Cl0p hackers
Cl0p (also Cl0P) is a Russian-speaking cybercriminal group specializing in data theft and extortion. The Canadian Centre for Cyber Security assesses it as a financially motivated group likely based in one of the Commonwealth of Independent States countries; the group is linked to the TA505/FIN11 cluster.
Cl0p has repeatedly carried out large-scale attacks by exploiting vulnerabilities in widely used enterprise software, including MOVEit. Western cybersecurity experts link the group's activities to the Russian-speaking cybercriminal ecosystem.
Recently, Russian hackers launched a global cyber campaign aimed at compromising accounts on the Signal and WhatsApp messaging apps.
Russian hackers were also reported to have breached British military bases and stolen classified documents.