{"id":92434,"date":"2023-06-07T07:00:00","date_gmt":"2023-06-07T07:00:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/?p=92434"},"modified":"2023-06-07T07:00:00","modified_gmt":"2023-06-07T07:00:00","slug":"clop-cyber-gang-claims-moveit-attack-and-starts-harassing-victims","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=92434","title":{"rendered":"Clop cyber gang claims MOVEit attack and starts harassing victims"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/06\/clop-cyber-gang-claims-moveit-attack-and-starts-harassing-victims.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The <a href=\"https:\/\/www.computerweekly.com\/news\/365534861\/Clop-ransomware-booms-in-March-as-Fortra-zero-day-pays-off-for-gang\">Clop (aka Cl0p) cyber extortion gang<\/a> has confirmed it is behind a series of major security breaches at organisations compromised via a SQL injection vulnerability <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/366539035\/Zero-day-vulnerability-in-MoveIt-Transfer-under-attack\">in Progress Software\u2019s MOVEit file transfer product<\/a>, and is threatening to start publishing the data it has stolen in seven days\u2019 time.<\/p>\n<p>Among the organisations blackmailed by the Russia-based cyber criminals are the BBC, Boots and British Airways (BA), all of which appear to have been victimised <a href=\"https:\/\/www.zellis.com\/resources\/press-and-media\/statement-on-moveit-transfer-data-breach\/\">through MOVEit user Zellis<\/a>, a supplier of payroll and human resources software and services. The data of more than100,000 individual employees across all three organisations is thought to have been stolen.<\/p>\n<p>Other known victims compromised via Zellis include the University of Rochester in the state of New York, and the provincial government of Nova Scotia in Canada.<\/p>\n<p>In a statement posted to its dark web leak site, which has been reviewed by Computer Weekly, Clop\u2019s operatives \u2013 who continue to labour under the delusion that they are providing <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/penetration-testing\">penetration testing services<\/a> \u2013 stated that the gang had stolen data from hundreds of companies.<\/p>\n<p>\u201cThis is announcement to educate companies who use Progress MOVEit product that chance is that we download a lot of your data as part of exceptional exploit. We are the only one who perform such attack and relax because your data is safe,\u201d the operative wrote.<\/p>\n<p>The Clop gang is giving victims until Wednesday 14 June to contact them or else it will post their details and data on its leak site. As has become standard practice in cyber ransom negotiations, it is offering victims the chance to review a small selection of the purloined material as proof of its intentions.<\/p>\n<p>The operative added that it had erased all data obtained from governments, city authorities and law enforcement, implying that some such organisations were compromised.<\/p>\n<p>A BBC spokesperson said: \u201cWe are aware of a data breach at our third-party supplier, Zellis, and are working closely with them as they urgently investigate the extent of the breach. We take data security extremely seriously and are following the established reporting procedures.\u201d<\/p>\n<p>Computer Weekly contacted BA and Boots in relation to the latest developments, but neither organisation had responded at the time of publication.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Next steps for MOVEit users\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Next steps for MOVEit users<\/h3>\n<p>Jim Tiller, CISO at <a href=\"https:\/\/www.nashsquared.com\/\">Nash Squared<\/a>, a global technology and talent provider, said that any organisation that has used MOVEit must now assume that their data, or the data of their customers, is now in Clop\u2019s hands.<\/p>\n<p>\u201cThese organisations need to urgently review and categorise all their information assets that are likely to have been stolen to understand what represents the greatest threat to extortion and prioritise accordingly,\u201d said Tiller.<\/p>\n<p>\u201cFrom there it\u2019s about assessing the risks associated with the exposure of the information, not only to the company but its clients, partners, affiliates and with those where information was exchanged. Without these critical steps responding to ransom demands and determining a course of action will be reactive and ineffective.\u201d<\/p>\n<p>Tiller additionally explained that organisations would need to come to terms with the fact that multiple organisations might be exploited for the same data, so even if one victim pays up, their information may still be leaked if another party resists Clop\u2019s demands.<\/p>\n<p>He said that unfortunately, this was one of the inherent risks of a multi-tenant cloud environment, and it may also mean that payments would not be covered by cyber insurance policies.<\/p>\n<p>\u201cMany insurers will have clauses that are very similar to acts of God or mass events that exclude such attacks from coverage. Therefore, if companies haven\u2019t already reviewed their policy with their provider, they need to as soon as possible,\u201d said Tiller.<\/p>\n<p>Jake Moore, global cyber security advisor at <a href=\"https:\/\/www.eset.com\/\">ESET<\/a>, added: \u201cAlthough it is never advised to pay ransom demands to cyber criminals, there is an inevitable risk that some of the targeted companies will succumb to the pressure. This will only fuel the fire and continue the cycle of this devastating criminal group.<\/p>\n<p>\u201cIt is more important that the companies affected are open and honest with their employees and customers offering support in how to protect themselves and how to spot follow up phishing and smishing attacks.\u201d<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Ransoms without ransomware\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Ransoms without ransomware<\/h3>\n<p>As previously reported, the nature of the MOVEit vulnerability that Clop exploited \u2013 <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-34362\">CVE-2023-34362<\/a> \u2013 is unlikely to provide sufficient access to deploy an actual ransomware locker, and there is no evidence that any of the known victims have had their systems encrypted.<\/p>\n<p>This makes the incident a case of straight-up data theft and extortion, something that is becoming increasingly commonplace, and a tactic favoured by Clop during its previous crime sprees.<\/p>\n<p>Moore said that the approach adopted by Clop this time around further deviated from the norm because more typically it would send its victims ransom demands with a predetermined amount chosen by them. This has not happened in this instance.<\/p>\n<p>\u201cThis decision is likely to stem from the overwhelming magnitude of the ongoing hack which is still affecting large numbers of systems worldwide and potentially overpowering the capabilities of Clop itself,\u201d he said.<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>The Clop (aka Cl0p) cyber extortion gang has confirmed it is behind a series of major security breaches at organisations compromised via a SQL injection vulnerability in Progress Software\u2019s MOVEit file transfer product, and is threatening to start publishing the data it has stolen in seven days\u2019 time. Among the organisations blackmailed by the Russia-based [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":92435,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-92434","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/92434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=92434"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/92434\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/92435"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=92434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=92434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=92434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}