HomeSecuritySchneider Electric confirms internal platform breach

Schneider Electric confirms internal platform breach

Schneider Electric has confirmed a breach of a developer platform, following claims by a hacker that 40GB of data from the company's JIRA server.

Schneider Electric breach

“Schneider Electric is investigating a cybersecurity incident involving unauthorized access to one of our internal platforms hosted in an isolated environment,” Schneider Electric told BleepingComputer.

The company said that cybersecurity experts were immediately mobilized to respond to the incident and explained that its products and services remain unaffected.

See also: Nokia investigates breach claims – Hacker says he stole source code

Schneider Electric is a French multinational company specializing in management energy. It manufactures a variety of products, from household electrical components to industrial control and enterprise-level building automation products.

Over the weekend, an attacker known as “ Grep ” said he had breached the company’s systems. Specifically, he said he compromised Schneider Electric’s Jira server using exposed credentials. After initially gaining access , he said he used a MiniOrange REST API to steal 400,000 rows of user data, which includes 75,000 unique email addresses and full names for Schneider Electric employees and customers

In a post on a dark web site, the attacker jokingly demands $125,000 in “Baguettes” to keep the data.

See also: Cisco: Data theft from DevHub portal will not lead to new breaches

“This breach has compromised critical Schneider Electric data, including projects, issues, and plugins, along with more than 400,000 rows of user data. In total, more than 40 GB of Compressed Data is affected,” Grep’s post states.

Grep told BleepingComputer that he and his partners have created a new hacking group, the International Contract Agency (ICA), which does not blackmail the companies it breaches. Instead, if a company does not report a breach within 48 hours, the group will leak the stolen data.

Schneider Electric confirms internal platform breach

Schneider Electric confirmed the breach, so we'll see if the attackers keep their word.

As technology continues to rapidly evolve, it is vital for companies like Schneider Electric to prioritize cybersecurity continuously and adapt to the ever-changing threat landscape. This includes regularly updating security protocols, implementing comprehensive employee training programs, and monitoring and improving their systems.

By taking a proactive approach to cybersecurity, companies can minimize the risk of a data and protect their customers’ sensitive information. The Schneider Electric breach serves as an important reminder that even with advanced security measures, constant vigilance and adaptation are essential to protect against cyber threats.

See also: Los Angeles: HACLA breached – Cactus ransomware responsible?

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

A proactive approach to security is crucial to maintaining customer and partner trust, especially in today's digital age where data breaches are becoming increasingly common.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS