Clop Ransomware Attack on Schneider Electric

Year

2023

Month

June

Reference number

20230609

Impact area

Shore

Incident location

France

Incident country

France

Victim country

France

Victim identity

Schneider Electric

Victim Type

Energy company

Method

Ransomware

Attacker country

Russia

Summary:

In June 2023, Schneider Electric, a multinational company specializing in digital automation and energy management, was targeted by the Clop ransomware gang in France. The attack exploited a zero-day vulnerability in the MOVEit Transfer software, developed by Progress Software. Clop listed Schneider Electric and other companies, including Siemens Energy and Cognizant, on its darkweb site, pressuring them to pay extortion fees to avoid data disclosure. Despite Schneider Electric's efforts to mitigate the vulnerability, Clop claimed to have stolen data from the company's systems. The MOVEit vulnerability has led to breaches in over 100 organizations, including Shell, PwC, and British Airways. Schneider Electric's response highlighted the importance of proactive cybersecurity measures and rapid incident response. The incident underscores the widespread impact of the MOVEit vulnerability, affecting various organizations globally.

Reference URL

https://www.crn.com/news/security/schneider-electric-probing-moveit-claim-by-cybercrime-group
https://www.csidb.net/csidb/incidents/984d5d31-7301-40cd-86ae-a6b8af8d6f4b/
https://www.securityweek.com/siemens-energy-schneider-electric-targeted-by-ransomware-group-in-moveit-attack/