News

Industries

Companies

Jobs

Events

People

Video

Audio

Galleries

Submit content

My Account

Advertise with us

Shell hit by massive hack attack

Shell is one of 50 companies — including Philips, Fiserv, and GE — that were reportedly hit by a massive hack attack. The hacking group Cl0p claims it stole roughly 89 gigabytes of data from Shell, including engineering drawings, photos of facilities, scans of facility testing reports, and project plans.
A view shows a logo of a Shell petrol station in South East London, Britain. Image credit: Reuters/May James/File Photo
A view shows a logo of a Shell petrol station in South East London, Britain. Image credit: Reuters/May James/File Photo

Reuters reports that a post on the site of a prolific hacking group known for exploiting software vulnerabilities to attack multiple targets simultaneously claimed it had stolen large volumes of data ​from nearly 50 companies worldwide.

Cybersecurity compromise

Philips said Cl0p had targeted it while Shell said it was aware of a recent “possible incident”, confirming an earlier report on Thursday by Dutch media outlet BNR.

“We are working with our ​security teams and relevant experts to investigate the situation,” a Shell spokesperson said.

“Philips has identified ​and contained an attempted cybersecurity compromise of a specific enterprise server related to ⁠internal data,” Philips said in a statement, adding that the incident does not impact customer environments.

A ​spokesperson for Fiserv said the company is aware of the threat actor’s claims, but “based on our comprehensive ​review to date”, it had found no evidence that customer, banking, transaction or personal data had been compromised, or that its operating environment had been affected.

A GE spokesperson said the company is aware of the claim, and had “initiated ​our cyber response protocols and are working to assess the potential issue.”

Alerts?

Reuters could not independently verify the hacking group’s claims about the type of data it stole and how much of it. The hackers did not respond ‌to a request for comment.

While it’s unclear how the hackers allegedly accessed the companies, Ransom-ISAC, an industry information-sharing group, issued a notice on 22 July warning that the hacking group was exploiting vulnerabilities in PTC Windchill and FlexPLM, software used to support engineering and manufacturing processes.

Boston-based PTC did not immediately ​respond to a request ​for comment. The company has issued multiple security notices on its website, dating back to 18 June, urging customers to apply a patch for a vulnerability and sharing details about an unnamed attacker targeting its products.

Brandon Parsons, threat intelligence manager at Ascent Solutions and the author of the Ransom-ISAC advisory, said some companies began receiving notices from Cl0p on 19 July or 20 July. The group focuses on vulnerabilities in key software packages rather than specific companies, he said, ⁠calling ​them “professional data extortionists.”

“They don’t really target a specific company; they ​target a specific zero-day vulnerability and go after it,” Parsons said, referring to previously unknown bugs that software vendors haven’t ​yet issued patches for.

Source: Reuters

Reuters, the news and media division of Thomson Reuters, is the world's largest multimedia news provider, reaching billions of people worldwide every day.

Go to: https://www.reuters.com/
More news
Let's do Biz