Back Computing Cyber gang claims to have breached dozens of multinationals, stolen data
The Clop cybercrime group claims to have stolen has stolen gigabytes of data from almost 50 multinational firms, including Shell, Philips, GE and Fiserv.
On its leak site, the Russian-speaking gang said it had stolen large volumes of data including 89GB from Shell and 13.5GB from Philips. The claims have not been independently verified.
The data exfiltrated from the two Netherlands-headquartered firms reportedly includes engineering plans, blueprints, photos of facilities and projections.
The companies involved have largely downplayed the group’s claims .
Philips said it had contained an attack and that customers are not affected. Shell said it was investigating a recent possible incident, and Fiserv said it believed no sensitive customer data had been compromised.
The alleged attack comes after security researchers reported in July that Clop (alternatively spelled Cl0p) actors were exploiting PTC Windchill and FlexPLM vulnerabilities to conduct data theft and extortion campaigns against manufacturing, aerospace, automotive and retail firms.
If confirmed it would fit with Clop's more recent operating model of exploiting a vulnerability as quickly and widely as possible, stealing data and then extorting the victims. Previously the gang was best known for ransomware attacks.
Last year, the gang conducted an extensive extortion campaign targeting Oracle E-Business Suite deployments, with victims including Harvard University, The Washington Post and Envoy Air.
In 2023, the group claimed responsibility for an attack that affected a wide range of companies , including British Airways, Boots and the BBC with an attack that exploited a flaw in the file transfer tool MOVEit.
Despite the 2021 arrest of six alleged Clop members in Ukraine, the group appears to have survived largely intact. Subsequently it carried out major extortion campaigns exploiting Accellion, GoAnywhere, MOVEit, Cleo and Oracle software.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
