The Cactus ransomware gang claims to have stolen 1.5TB of data from Schneider Electric, following a successful attack last month.

To confirm the theft, the hackers leaked 25 MB of the alleged data to their dark web site. There are also several screenshots showing US citizen passports and contract documents.
On January 17, the hackers behind the Cactus ransomware gained access to Sustainability Business . The gang is now blackmailing the company, threatening to leak all stolen data if the ransom is not received.
See also: Cactus Ransomware group hacked Swedish company Coop
At this time, we do not know exactly what data was stolen. In general, Schneider Electric's Sustainability Business provides renewable energy and regulatory compliance consulting services to many large companies worldwide
Therefore, the data that the hackers may include sensitive information about customers' industrial control and automation systems and more.
Cactus ransomware is a relatively new ransomware operation, which emerged in March 2023 with double extortion attacks . Hackers compromise corporate networks using purchased credentials , partnering with various malware distributors , carrying out phishing attacks , or exploiting security vulnerabilities .
After gaining access to a target's network, hackers spread and steal sensitive data. They then threaten victims with data.
Cactus ransomware has added more than 100 companies to its data leak website. The attackers have already leaked some of the victim companies' data online or are threatening to do so while still negotiating for a ransom payment.
See also: CACTUS ransomware: Exploits Qlik Sense vulnerabilities

Impact of a data breach
The first and most immediate impact of a breach is the loss of trust from Schneider Electric customers. Customers may be concerned about the security of their data and seek alternative solutions.
Second, Schneider Electric could face legal repercussions. If the stolen data contained personal information , the company could face lawsuits for data protection violations.
Third, the company could suffer financial losses. Data loss can lead to business interruption, while the need to restore systems and deal with legal repercussions can be costly.
See also: Authorities “destroyed” LockBit ransomware
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, this breach could have long-term repercussions for Schneider Electric's corporate reputation . The failure to protect its customers ' data could affect the company's image in the future.
Source: www.bleepingcomputer.com
