HomeSecuritySchneider Electric: Victim of Cactus ransomware

Schneider Electric: Victim of Cactus ransomware

Schneider Electric was reportedly attacked by Cactus ransomware, which led to the theft of corporate data.

Schneider Electric Cactus ransomware

According to BleepingComputer, the attack hit the company's Sustainability Business division on January 17. As a result, there were some outages on part of Schneider Electric's Resource Advisor cloud platform

The Cactus ransomware gang allegedly stole a lot of corporate data during the cyberattack and is now threatening to leak that data.

At this time, we do not know what data was stolen, but the Sustainability Business division provides consulting services to business organizations (e.g., advice on renewable energy solutions and assistance with complex climate regulatory requirements).

See also: Education is one of the biggest targets of ransomware

Schneider Electric customers include Allegiant Travel Company, Clorox, DHL, DuPont, Hilton, Lexmark, PepsiCo and Walmart.

In a statement to BleepingComputer, Schneider Electric confirmed the Cactus ransomware attack and data breach. However, the company stressed that the attack was limited to its Sustainability Business division.

“From a recovery perspective, Sustainability Business is executing remediation steps to ensure that business platforms are restored to a secure environment. Teams are currently testing the functionality of the affected systems with the expectation that access will be restored within the next two business days,” the company said.

Schneider Electric: Victim of Cactus ransomware

Schneider Electric also said it is continuing its investigation into the data and will notify affected customers, providing information and assistance as needed.

Schneider Electric is a French multinational company dealing in energy and automation products (for homes and businesses).

See also: Faust, Kasseika, Kuiper: New ransomware gangs in the threat landscape

Ransomware attacks are one of the most significant cybersecurity threats worldwide . Companies like Schneider Electric must work hard to protect their customers and systems from such attacks. 

Schneider Electric must adopt a number of measures to protect against ransomware attacks. These measures include security programs and protocols, such as updating software and security systems to remain effective and able to deal with the latest threats. 

Additionally, the company must use an advanced threat detection and remediation. This system constantly monitors the company's computing volumes for signs of a breach or attempted attack, while simultaneously updating the corresponding security systems. 

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Also, backups of important data and continuous updating of systems are essential to address vulnerabilities that hackers could exploit.

The company had been targeted previously, during the widespread MOVEit data theft attacks by the Clop ransomware gang.

Schneider Electric: Victim of Cactus ransomware

Cactus ransomware: Attack on Schneider Electric

The Cactus ransomware operation began in March 2023. Like all ransomware operations, threat actors breach corporate networks through purchased credentials, partnerships with malware distributors, phishing attacks, or by exploiting security vulnerabilities.

After accessing a network, data. After stealing and gaining privileges on the network, threat actors encrypt files and leave behind ransom notes.

See also: Akira ransomware: Cyberattack on Bucks County emergency system

Attackers demand ransom both for decrypting the systems and for not leaking the stolen data (something known as double blackmail).

Currently, there are more than 80 companies listed on the Cactus data breach website. Some of them have already had their data leaked, while others have been warned about information leaks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS