Russian hackers claim to have hacked nearly 50 companies — Reuters
The Russia-linked hacking group Cl0p claimed to have stolen significant amounts of data from nearly 50 companies around the world. Among the companies named by the attackers are Philips, Shell, Fiserv, and GE.
Philips confirmed an attempted cyberattack. The company stated that it had detected and contained an attempt to compromise a single corporate server containing internal data. According to the company, customer environments were not affected.
Shell also reported a possible cyber incident. A company spokesperson stated that cybersecurity specialists and outside experts are investigating the situation.
Fiserv stated that it is aware of the hackers’ claims but has not yet found any signs of compromise of customer data, banking and payment information, or personal data. Additionally, according to the company, its operational environment was not affected.
GE has not yet commented on the situation.
Reuters was unable to independently verify Cl0p’s claims regarding what specific data may have been stolen and to what extent. The hackers themselves did not respond to the agency’s inquiry.
According to Reuters, Cl0p may have exploited vulnerabilities in PTC’s Windchill and FlexPLM software, which are used in design and manufacturing processes.
The Ransom-ISAC industry group had warned about the exploitation of these vulnerabilities as early as July 22. PTC also published a security advisory and urged customers to install the relevant updates.
Cyber threat analyst Brandon Parsons, who authored the Ransom-ISAC alert, said that some companies began receiving messages from Cl0p on July 19 or 20.
According to him, the group focuses not on specific companies, but on vulnerabilities in popular software. Parsons called Cl0p “professional data extortionists.”
Cl0p (also Cl0P) is a Russian-speaking cybercriminal group that specializes in data theft and extortion. The Canadian Cyber Security Center assesses it as a financially motivated group likely based in one of the CIS countries; the group is linked to the TA505/FIN11 cluster.
Cl0p has repeatedly carried out large-scale attacks exploiting vulnerabilities in popular enterprise software, including MOVEit. Western cybersecurity experts link the group’s activities to the Russian-speaking cybercrime community.
Source: Reuters
Earlier, Microsoft warned of a new cyberattack by Russian hackers via Wi-Fi.
Microsoft is laying off thousands of employees due to AI-related costs.