Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2023_110
A company producing industrial automation for the maritime sector is victim of a ransomware attack.
Day Month Year Country Activity Incident Type
26 June 2023 France Industry Virus/Ransomware

Summary

The victim is a leading multinational company based in France. The corporation has a prominent global presence, boasting an annual revenue exceeding $37 billion. It is renowned for its expertise in digital automation and energy management, with its products being integral to numerous crucial sectors around the globe.

According to sources, on May 30th, 2023, the company acknowledged potential vulnerabilities in the Progress MOVEit Transfer software. The company acted swiftly by implementing the available mitigation measures to safeguard data and infrastructure, keeping a vigilant watch over the evolving situation. However, a twist emerged on June 26th, 2023, when the company was alerted to claims suggesting that they had fallen prey to a cyber-attack related to MOVEit vulnerabilities.

The victim has yet to confirm the legitimacy of Cl0p's allegations.

Victim

Schneider Electric

Claimed/Reported Threat Actor

Cl0p

Origin

Cybercrime

Main impact

Availability

References

Recommendations to Industry to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Monday, 11th December 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.