
The ransomware group Clop has been linked to ransomware attacks against General Electric, Philips, Shell and 40 other companies. Clop recently claimed on their leak site to have successfully breached these company's systems and stolen data that includes backup files, project plans, photos of facilities, drawings, diagrams, blueprints, and more.
GE stated that the company is aware of the claim and working to address potential issues. Philips acknowledged the attack, but stated the incident was contained and would not impact customers. Shell has stated it is investigating a potential security incident.
Although none of the impacted companies have provided any details on the attack, Clop is claiming it stole 89GB of data from Shell, 15.5GB from Philips and 391GB from GE. The current quantities and scope of data stolen is probably seen as a minimal concern. However, the bigger issue is how the hacking group could leverage this information in generating a bigger, broader, more disruptive and more expensive attack down the road.
The ever-evolving capabilities of artificial intelligence means hackers are able to scale up attacks with unprecedented speed, and with less information.
While few details have been made available, it is thought that the group took advantage of zero-day and other vulnerabilities in product lifecycle management software platforms to access and extract the data being ransomed. That tactic would be consistent with the group's other attacks, including its 2023 hack of the MOVEit file transfer platform that impacted over 2,700 organizations globally.
The group has become notorious enough that the U.S. State Department has sponsored a $10 million reward for any information linking Clop's attacks to a foreign government.
"Cl0p’s playbook hasn’t been a mystery for years," states Pete Luban, Field CISO at AttackIQ. "They’ve repeatedly targeted widely used enterprise software, exploited known weaknesses, and used stolen data as leverage. Defenders have had plenty of opportunities to study how they operate.
"The challenge is turning that knowledge into action. CTEM gives organizations a way to continuously identify the exposures that are most likely to matter, rather than treating every vulnerability as equally urgent. From there, adversarial testing can show whether existing controls actually stop the techniques Cl0p is known to use.
"Patching is important, but it only addresses one piece of the problem. If a group with a well-documented history can still walk through the same kinds of gaps, organizations need to ask whether they’re truly reducing exposure or simply reacting to the latest headline.”




















