{"id":92880,"date":"2023-06-15T08:15:00","date_gmt":"2023-06-15T08:15:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/?p=92880"},"modified":"2023-06-15T08:15:00","modified_gmt":"2023-06-15T08:15:00","slug":"clop-begins-naming-alleged-moveit-victims","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=92880","title":{"rendered":"Clop begins naming alleged MOVEit victims"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/06\/clop-begins-naming-alleged-moveit-victims.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>As it had previously threatened, the Clop cyber crime cartel has started publicly naming victims allegedly compromised via <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/podcast\/Risk-Repeat-MoveIt-Transfer-flaw-triggers-data-breaches\">a SQL injection flaw in Progress Software\u2019s MOVEit managed file transfer product<\/a>, who have resisted its extortion attempt.<\/p>\n<p>Clop, which is believed to be based in Russia, told users of the MOVEit Transfer product last week that they had <a href=\"https:\/\/www.computerweekly.com\/news\/366539357\/Clop-cyber-gang-claims-MOVEit-attack-and-starts-harassing-victims\">seven days to comply with its demands<\/a>. <a href=\"https:\/\/www.computerweekly.com\/news\/366541722\/Clops-MOVEit-ransom-deadline-expires\">This deadline passed yesterday<\/a> (14 June), and true to its word, Clop began to add the details of new victims, up to a total of 12, to its dark web leak site at around 6pm UK time.<\/p>\n<p>Among the first tranche of names are fuel giant <a href=\"https:\/\/www.shell.co.uk\/\">Shell<\/a>, the <a href=\"https:\/\/www.uga.edu\/\">University of Georgia<\/a> in the US, and investment fund <a href=\"https:\/\/www.putnam.com\/\">Putnam<\/a>. Also included are a number of US banks, and organisations in the Netherlands and Switzerland.<\/p>\n<p>A Shell spokesperson confirmed that the organisation had been affected by the incident.&nbsp;\u201cWe are aware of a cyber security incident that has impacted a third-party tool from Progress called MOVEit Transfer, which is used by a small number of Shell employees and customers,\u201d they said.<\/p>\n<p>\u201cThere is no evidence of impact to Shell\u2019s core IT systems. Our IT teams are investigating. We are not communicating with the hackers.\u201d<\/p>\n<p>Computer Weekly understands that unlike some other affected organisations, Shell was not affected via the systems of a third-party supplier or contractor.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Many more names to come\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Many more names to come<\/h3>\n<p>Not appearing on Clop&#8217;s leak site \u2013 at the time of writing \u2013 are the names of several known MOVEit victims, including <a href=\"https:\/\/www.computerweekly.com\/news\/366539413\/Victims-of-MOVEit-SQL-injection-zero-day-mount-up\">the BBC, Boots, British Airways<\/a>, <a href=\"https:\/\/www.computerweekly.com\/news\/366541003\/Ofcom-data-stolen-in-MOVEit-cyber-attack\">Ofcom<\/a> and TfL.<\/p>\n<p>However, it is important to note that due to the high number of victims it has likely compromised \u2013 more than 2,000 instances of MOVEit Transfer were exposed to the public internet last week, and figure does not include compromised customers of the instance owners \u2013 Clop is likely staggering its release.<\/p>\n<p>As such, the non-appearance of some high-profile names at this early stage is no indication that the victims have engaged with Clop or paid a ransom, and no such indication should be inferred.<\/p>\n<p><a href=\"https:\/\/www.secureworks.com\/\">Secureworks Counter Threat Unit<\/a> threat research director Chris Yule said it would likely take the cyber criminals some time to work through the victims.<\/p>\n<p>\u201cIt remains to be seen if there will be one dump or a drip feed, [but] the GoAnywhere victims were posted in batches over a period of 14 days,\u201d said Yule.<\/p>\n<p>\u201cThe first names Clop have posted included a number of US-based financial services companies. Whilst the upload has just begun, we anticipate that the balance of victims will likely be based in the US, as the majority of MOVEit servers on the internet were based there.\u201d<\/p>\n<p>H\u00fcseyin Can Yuceel, a threat researcher at <a href=\"https:\/\/www.picussecurity.com\/\">Picus Security<\/a>, said that releasing the details of its victims more slowly could serve to pressure others into paying a ransom, and it was clear that Clop had not been bluffing in its threats.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"What victims should do next\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>What victims should do next<\/h3>\n<p>While no ransomware locker has been executed on any of the victim systems so far \u2013 this is consistent with Clop\u2019s modus operandi in such situations \u2013 the playbook for how to deal with a data exfiltration and extortion incident is broadly similar to a situation where data encryption has taken place.<\/p>\n<p>\u201cPrevention is always the number one priority against ransomware attacks. [Afterwards] there is not much that can be done,\u201d said Can Yuceel.<\/p>\n<p>\u201cEven if backups are in place, ransomware groups can release their victims&#8217; sensitive data and harm their reputation. Law enforcement agencies advise businesses not to pay ransoms because ransomware groups may not deliver the decryption key after the payment. There are also other risks with ransom payments.<\/p>\n<p>\u201cWe have observed that organisations known to pay the ransom are much more likely to be targeted by the same or other ransomware groups in the future. Ransom payments can also perpetuate the ransomware threat and are used to fund other illegal activities.\u201d<\/p>\n<p>Can Yuceel warned that for the UK\u2019s growing roster of victims \u2013 which now also includes <a href=\"https:\/\/www.adaresec.com\/\">Adare SEC<\/a>, a specialist customer comms services supplier for the financial and insurance sector with customers including <a href=\"https:\/\/www.insurancejournal.com\/news\/international\/2023\/06\/15\/725327.htm\">Legal &amp; General, AON and Allianz<\/a> \u2013 should be particularly wary of engaging or paying a ransom due to strict financial regulations covering payments to Russian criminal organisations.<\/p>\n<p>\u201c<a href=\"https:\/\/www.gov.uk\/government\/organisations\/office-of-financial-sanctions-implementation\">The Office of Financial Sanctions Implementation<\/a> considers ransom payments as a breach of financial sanctions, which is a serious criminal offence and can carry a custodial sentence and the imposition of a monetary penalty,\u201d he said.<\/p>\n<p>\u201cVictims in the UK should therefore <a href=\"https:\/\/www.ncsc.gov.uk\/information\/moveit-vulnerability\">report the attack to the National Cyber Security<\/a> Centre and request support for managing the cyber incident if needed.\u201d<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>As it had previously threatened, the Clop cyber crime cartel has started publicly naming victims allegedly compromised via a SQL injection flaw in Progress Software\u2019s MOVEit managed file transfer product, who have resisted its extortion attempt. Clop, which is believed to be based in Russia, told users of the MOVEit Transfer product last week that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":92881,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-92880","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/92880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=92880"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/92880\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/92881"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=92880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=92880"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=92880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}