24-hour coverage PT
Breaking News Brazil and the world, minute by minute
Technology

Hacker group says it stole data from almost 50 companies, including Philips and Shell

Cybercrime; hacker; digital crimes; virtual crimes Kevin Horvart/Unplash A group of hackers known for exploiting security flaws in software to attack several companies at the same time claimed to have stolen large volumes of data from...

Hacker group says it stole data from almost 50 companies, including Philips and Shell
365 Summary

Philips confirmed that it was targeted by the Cl0p group and reported that it identified and contained an attempted invasion of a corporate server linked to internal data. According to the company, the incident did not affect customer environments.

  • Shell said it is aware of a recent "potential incident" and is working with its security teams and external experts to investigate the matter.
  • Hacker attack takes city hall websites offline Invasion hits Fiserv stated that it is aware of the hackers' allegations, but that, after a complete analysis carried out to date, it has...

Editorial reading aid based only on information contained in this story and its identified source.

Cybercrime; hacker; digital crimes; virtual crimes Kevin Horvart/Unplash A group of hackers known for exploiting security flaws in software to attack several companies at the same time claimed to have stolen large volumes of data from almost 50 companies around the world, including Philips, Shell, Fiserv and General Electric. The allegation was published on the group's own website. Philips confirmed that it was targeted by the Cl0p group and reported that it identified and contained an attempted invasion of a corporate server linked to internal data. According to the company, the incident did not affect customer environments. Shell said it is aware of a recent "potential incident" and is working with its security teams and external experts to investigate the matter. Hacker attack takes city hall websites offline Invasion hits Fiserv stated that it is aware of the hackers' allegations, but that, after a complete analysis carried out to date, it has found no evidence of compromise of customer data, banking information, transactions or personal data, nor of any impact on its systems. General Electric did not respond to requests for comment. Reuters was unable to independently verify whether the hackers actually stole the data, nor what volume or type of information they obtained. The Cl0p group also did not respond to interview requests. It is still unclear how the attackers accessed the companies Despite the uncertainty surrounding how the companies were hacked, Ransom-ISAC, an organization that shares information about cyber threats, warned on July 22 that Cl0p was exploiting security flaws in the PTC Windchill and FlexPLM programs, software used by companies to manage engineering projects and manufacturing processes. PTC, the company responsible for the programs, did not comment on the case. Since June 18, it has published several security advisories directing its customers to install an update that fixes the vulnerability and informing them of attacks against its products. Hacker DC Studio/Freepik According to Brandon Parsons, threat intelligence manager at Ascent Solutions and author of the Ransom-ISAC alert, some companies began receiving notifications from Cl0p between July 19 and 20. He states that the group does not usually choose specific victims, but rather exploits the same flaw in widely used software. "They don't attack a specific company. They find a zero-day vulnerability and exploit that flaw," Parsons said. A zero-day vulnerability is a security flaw unknown to the software manufacturer and which does not yet have a fix available, making thousands of potential users targets of simultaneous attacks.