By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
IndebtaIndebta
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Notification Show More
Aa
IndebtaIndebta
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
Indebta > Markets > Stocks > Factbox-Who is behind the sweeping MOVEit hack?
Stocks

Factbox-Who is behind the sweeping MOVEit hack?

News Room
Last updated: 2023/06/28 at 5:54 AM
By News Room
Share
5 Min Read
SHARE

© Reuters. FILE PHOTO: A man holds a laptop computer as cyber code is projected on him in this illustration picture taken on May 13, 2017. REUTERS/Kacper Pempel

By Raphael Satter

(Reuters) – The cl0p ransomware gang is claiming a new set of victims from its hack of the MOVEit file transfer protocol, taking credit on Tuesday for having stolen data from the University of California, Los Angeles, Siemens Energy, Abbvie Inc and Schneider Electric (EPA:), among others.

The total number of recent victims from the online extortion ring has reached 121 organizations, according to Brett Callow, whose cybersecurity company Emsisoft helps companies respond to digital shakedown attempts. He said that at least 15 million people were affected.

Here’s what is known about cl0p and its recent rampage.

Who are the hackers?

Cl0p’s identity and location are not publicly known. But security researchers say the group is Russia-linked or Russian-speaking and its name could be a play on the Russian word for “bug.” In 2021, Ukrainian authorities announced the arrests of six people tied to cl0p, but it’s not clear that they were core members of the group, which continued to hack victims.

Cl0p is a ransomware-as-a-service gang, meaning that it hires out its software and infrastructure for other cybercriminals in return for a cut of the proceeds.

The group helped pioneer the practice of double-extortion, where cybercriminals take files hostage by encrypting them – then threaten to leak them online unless a payment is made. Japanese cybersecurity firm TrendMicro described cl0p as “a trendsetter for its ever-changing tactics.”

The hackers – who sometimes spell their name “CLOP” – didn’t immediately return an email seeking comment.

How did they rack up so many victims?

Cl0p was able to take advantage of a previously undiscovered flaw in a popular file transfer program – MOVEit Transfer – to steal data from a wide swathe of organizations, some of whom in turn were handling data belonging to yet more organizations.

Plundering file transfer protocols has become increasingly popular as hackers shift from encrypting data to simply stealing files and threatening to release them unless a ransom is paid.

If a victim doesn’t pay, cl0p posts their identity to its darknet site – a name-and-shame tactic that has been playing out over the past several weeks.

Who has been affected?

Publicly claimed victims include entertainment company Sony (NYSE:), major accounting firms EY and PWC, energy giant Shell (LON:) PLC and leading U.S. pension fund Calpers.

Government departments – including the U.S. Energy Department and the U.K. telecom regulator – have also been hit.

Many of the organizations stress that the target of the hack is the file transfer service, not their systems. But because their data is nonetheless stolen, it’s little comfort to citizens, employees, clients and business partners whose information has been compromised.

It was working from public disclosures that Brett Callow of Emsisoft came up with the figure of 15 million individuals affected. But he said the true number was “likely much higher – and possibly much, much higher.”

What’s being done to stop them?

The wide-ranging and often indirect nature of the compromises has meant an avalanche of work for law enforcement and cybersecurity professionals.

“Everyone is overwhelmed,” said Charles Carmakal, the chief technology officer at Mandiant, which was recently acquired by Alphabet (NASDAQ:) Inc. In a message to LinkedIn he said that even the hackers were struggling with the workload.

“The past few weeks have been intense,” he said.

The FBI said it was “aware of and investigating the recent exploitation of a MOVEit vulnerability by malicious ransomware actors.” Earlier this month the U.S. government announced a $10 million reward for information linking cl0p – or any other hacking groups targeting American critical infrastructure – to foreign governments.

Read the full article here

News Room June 28, 2023 June 28, 2023
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
Beyond Meat: Why this strategist has ‘no interest’ in this meme stock

Watch full video on YouTube

‘Ghost jobs’ are adding another layer of uncertainty to the stalling jobs picture

Watch full video on YouTube

Harbor Dividend Growth Leaders ETF Q3 2025 Commentary (GDIV)

Harbor Capital is an asset manager focused on curating an intentionally select…

Digital bank N26 appoints UBS executive as new chief after fresh sanctions

Unlock the Editor’s Digest for freeRoula Khalaf, Editor of the FT, selects…

Gold’s decline could be the start of a correction. 📉

Watch full video on YouTube

- Advertisement -
Ad imageAd image

You Might Also Like

Stocks

Playa Hotels & Resorts (NASDAQ:PLYA) Delivers Strong Q4 Numbers By Stock Story

By News Room
Stocks

ON24 (NYSE:ONTF) Posts Better-Than-Expected Sales In Q4 By Stock Story

By News Room
Stocks

Evolent Health shares leap on Q4 earnings beat and upbeat guidance By Investing.com

By News Room
Stocks

Chuy’s (NASDAQ:CHUY) Reports Q4 In Line With Expectations But Stock Drops

By News Room
Stocks

Red River Bancshares raises dividend to $0.09 per share

By News Room
Stocks

Ecolab appoints Microsoft executive to board

By News Room
Stocks

Semilux secures $50 million equity deal with White Lion Capital

By News Room
Stocks

US government debt trajectory to push long-term yields higher, says PIMCO

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?