ZeroHour
The Recordpublished ()ingested

Tasmania: 150,000 individuals and businesses affected by Clop ransomware group

highRansomwareimportance 60CVE-2023-0669

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-0669
Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

7.2100% KEV ransomware PoC ×3
  • Fortra GoAnywhere MFT
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface)
Full article467 words · extracted from therecord.media · click to collapse

The government of the Australian state of Tasmania confirmed on Friday “approximately 150,000 individuals and businesses” in the island state were directly affected by the hack of Fortra’s GoAnywhere file transfer product.

In an update from the state’s minister for science and technology, Madeleine Ogilvie, the Tasmanian government said it is continuing to investigate the theft of data, which includes information regarding schoolchildren.

The state government has “proactively reached out by phone to those identified as vulnerable to ensure they have the supports in place,” said Ogilvie, who last week announced that 16,000 sensitive documents had been released by the Clop extortion group.

“Through extensive investigations by our cyber team, we have now identified approximately 14,000 additional individuals whose data may have been compromised. Out of an abundance of caution, those identified will be contacted today,” the minister said.

It is not clear what relation the 30,000 identified individuals have to the 150,000 individuals and businesses which the state government cited earlier.

Ogilvie had acknowledged earlier that the investigation into the attack indicated that “financial data from the Department for Education, Children and Young People may have been accessed in the global incident.”

While she said last week that more information was likely to be released, in Friday’s update Ogilvie added “there is no evidence that any further data has been released.”

However the government stated: “We continue to urge people to stay alert for any suspicious financial activity or attempted scams.”

The Clop ransomware group has published information stolen from dozens of companies and organizations after spending weeks exploiting a vulnerability in the popular GoAnywhere tool.

Governments, businesses and schools — from the City of Toronto and the Virgin company to Hitachi — have come forward to say data was stolen through the bug affecting GoAnywhere. Clop is the only hacking group confirmed to have exploited the vulnerability, which cybersecurity researchers track as CVE-2023-0669.

In February, Clop claimed it had attacked more than 130 organizations and it has slowly been adding names to its list of victims since then.

Fortra, the company behind GoAnywhere, has faced backlash for its response to the fiasco. Several customers told TechCrunch last week that the company told them their data was safe when it was not.

The Clop attack also has stirred criticism from the opposition Labor Party, which said Tasmania's Liberal government hasn't communicated effectively about the crisis and downplayed the sensitivity of the stolen data. Ogilvie said Labor officials were fearmongering and peddling misinformation about the government's response to the incident.

No previous article

No new articles

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/tasmania-data-breach-clop-150000-affected