The hacker group Cl0p he claimed to have stolen large amounts of data from nearly 50 companies in various countries, including Shell, Philips, GE and Fiserv the affected companies have launched investigations while doubts persist about the true extent of the leak and the method used to access their systems.
The campaign once again focuses on vulnerabilities present in enterprise software, Ransom-ISAC had warned in July that Cl0p was exploiting flaws in PTC Windchill and FlexPLM, two platforms used in engineering and manufacturing processes.
Shell and Philips investigate possible data theft
For their part, Shell he confirmed that he is aware of a possible recent incident and noted that his security teams are working with specialists to investigate what happened.
Cl0p claims to have obtained approximately 89 GB of information from the energy company, Among the allegedly stolen files are blueprints of energy facility projects, photographs of industrial sites, technical inspection reports, and planning documents. However, the existence and content of this information have not been independently verified.
Philips also acknowledged being targeted by Cl0p, the company reported that it detected and contained an attempted cybersecurity breach on a corporate server containing internal information. According to Philips, the incident did not affect its customers’ environments.
The hackers claim to have obtained approximately 13.5 GB of company data, including schematics, blueprints, and diagrams. At the time of the claims, no samples had been released to substantiate the alleged theft.
GE and Fiserv activate cybersecurity reviews
Meanwhile, GE indicated that it is aware of the group’s claims and has activated its incident response protocols to assess the situation.
Fiserv also confirmed that it is aware of the cybercriminals’ statements, following its initial review, the company stated that it found no evidence that customer data, banking information, transactions, or personal data had been compromised. The company also identified no impact on its operating environment.
Thus, there is a significant difference between Cl0p’s claims and what has been confirmed so far by the companies. The group claims to have obtained corporate information on a large scale, while several of the affected organizations continue to verify the extent of the incidents.
Vulnerabilities in PTC Windchill and FlexPLM under analysis
Although the vector used to access these companies has not been officially established, Ransom-ISAC issued a warning on July 22 about Cl0p activity against PTC Windchill and FlexPLM.
Both platforms are used in processes related to engineering, product management, and manufacturing, therefore, an exploitable vulnerability in this type of software can offer attackers a way to reach numerous organizations through the same campaign.
PTC had published security advisories since June and urged its customers to install updates to fix vulnerabilities. This approach aligns with the operational history attributed to Cl0p, instead of necessarily focusing on a specific company, the group looks for vulnerabilities present in platforms used by multiple organizations.
Cl0p targets vulnerabilities to attack multiple companies
Brandon Parsons, threat intelligence manager at Ascent Solutions and author of the Ransom-ISAC advisory, described the group as a professional operator dedicated to data extortion.
According to Parsons, Cl0p focuses its operations on specific software vulnerabilities that can grant access to multiple organizations. Some companies began receiving communications from the group around July 19 and 20. This strategy allows the same security failure become the gateway to a large-scale campaign.
For now, the full extent of the alleged data theft remains unconfirmed, investigations by Shell, Philips, GE, and Fiserv will be pivotal in determining what information may have been exposed and whether vulnerabilities associated with PTC software were indeed exploited in these incidents. It will also be crucial to determine whether sensitive data was exfiltrated, which systems were affected, and how long they may have remained exposed. As internal reviews proceed, the companies will need to cross-reference Cl0p’s claims with technical logs, forensic evidence, and potential unauthorized access before confirming the true scope of the campaign.
Source: Energy Now
Photo: Shutterstock