Hacking Group Claims Massive Data Theft from Nearly 50 Major Firms Including Shell and Philips

Deep News08-14 07:44

A hacking group known for targeting multiple organizations simultaneously via software vulnerabilities has declared it breached nearly 50 global companies, exfiltrating a substantial volume of data. The affected entities include Royal Philips NV, Shell, Fiserv, and General Electric.

Royal Philips NV has confirmed it was targeted by the Cl0p ransomware group, while Shell acknowledged it is investigating a "suspected security incident" after Dutch media first reported the development on Thursday.

A Shell spokesperson stated, "We are working with our internal security teams and relevant professionals to investigate this incident."

Royal Philips NV said in a statement that it had identified and blocked a cybersecurity attack attempt targeting a specific corporate server containing internal data, and that the incident had not impacted the customer environment.

A Fiserv spokesperson indicated the company is aware of the attacker's claims but, based on a "thorough review to date," has found no evidence of customer banking, transaction, or personal data exposure, nor any disruption to its operational environment.

General Electric did not immediately respond to requests for comment.

The exact method of intrusion remains unclear. An industry information-sharing body, the Ransomware Information Sharing and Analysis Center (Ransom-ISAC), issued an alert on July 22, stating the group was exploiting vulnerabilities in PTC's Windchill and FlexPLM software, which are used to assist engineering design and manufacturing processes.

Boston-based PTC did not respond to requests for comment. Since June 18, the company has published multiple security bulletins on its website, urging customers to install patches and disclosing details of attacks targeting its software by unknown attackers.

Brandon Parsons, threat intelligence director at Ascent Solutions and author of the Ransom-ISAC alert, said some companies received ransom notices from the Cl0p group as early as July 19 and 20. He described the group as a "professional data extortion gang" that targets vulnerabilities in mainstream software suites rather than specific companies.

Speaking about zero-day vulnerabilities—software flaws not yet publicly known or patched by vendors—Parsons noted, "They don't specifically target a single company. They target a specific zero-day vulnerability and use that as a springboard to launch attacks."

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

We need your insight to fill this gap
Leave a comment