Energy giant Shell impacted in Accellion hack
Full article578 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Shell is just the latest in a long line of victims.
Oil and gas company Shell is the latest organization to get caught up in the hack that targeted IT provider Accellion’s file-sharing platform, the energy company says.
The suspected criminal hackers behind the breach, who have gone after victims around the world using vulnerabilities in Accellion’s file transfer application (FTA), have accessed some personal data as well as data belonging to Shell stakeholders and subsidiaries, the company said on March 16. Shell had used the FTA to securely transfer large files.
The incident appears to have only impacted the Accellion file transfer service. Shell claims there is “no evidence” so far that the incident has affected Shell’s IT system itself.
Shell is working with authorities and regulators to investigate the incident, the firm said.
The list of companies that use Accellion’s FTA that have fallen victim to the Accellion hack continues growing by the day. A Michigan-based savings bank and the grocery chain Kroger have previously announced that they have been impacted as a result of Accellion’s breach. Jones Day, a prominent law firm, has also been hit, according to The Wall Street Journal. Other victims include the Reserve Bank of New Zealand, the state of Washington, Harvard Business School and cybersecurity company Qualys.
Palo Alto-based Accellion has been hit with a class action lawsuit in recent weeks that claims it failed to ensure “adequate security protocols” for the FTA.
The hackers involved in the Accellion hack have, in some cases, threatened to publish data stolen from victims.
Security researchers are tracking multiple overlapping hacking groups that appear to be involved the operation. A group known as UNC2546 appears to be the group behind the initial exploitation of the Accellion FTA zero-day vulnerabilities, according to FireEye researchers, who have also said that a group called UNC2582 appears to be using stolen data to extort victims.
UNC2582 has claimed in extortion emails to victims that it is linked with the threat actors behind Clop ransomware, according to FireEye.
UNC2582 has a track record of following through on threats to publish stolen data, according to FireEye.
FireEye has observed overlaps between these hacking groups and another attack team known as FIN11.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/shell-accellion-hack-victims/