In the UK, DHL has announced that it is investigating a data breach sourced back to its use of the MOVEit software, which was subsequently exploited by a Russia-based ransomware group, The Record reports.
In a statement to Recorded Future News, DHL confirmed that one of its software providers had been affected by the vulnerability affecting MOVEit, a file-sharing tool from Progress Software.
“Upon being made aware of the incident, DHL quickly launched an investigation working with relevant experts to understand the impacts,” a DHL spokesperson said. “This investigation is ongoing, and we will continue to communicate with those affected when we have more information to share."
The shipping giant is the latest big-name company to announce a breach related to the Clop ransomware gang’s exploitation of the MOVEit bug. Progress Software has patched the software, however, cybercriminals have reportedly continued to find unpatched targets.
Emsisoft researchers have been tracking the number of companies involved. They found that at least 383 organisations have been affected with the information of 20,421,414 people leaked as a result.
A number of organisations reportedly filed documents with regulators in Maine last week confirming that the data that was accessed through MOVEit. Some banks and financial institutions stated that hundreds of thousands of customers were affected while higher-profile organisations confirmed breaches with smaller numbers of victims.
Online poker cardroom PokerStars revealed that its breach involved the Social Security numbers of 110,291 people, while Pennsylvania-based Franklin Mint Federal Credit Union said 140,963 had their Social Security numbers accessed by Clop.
1st Source Bank had the sensitive data of 450,000 customers exposed through its use of MOVEit, it has since provided victims with two years of identity protection services. The majority of impacted organisations have taken similar action.
On July 21, researchers at Coveware released a report stating that the Clop ransomware group may end up earning anywhere from $75 million to $100 million solely from the MOVEit attack, with the sum “coming from just a small handful of victims that succumbed to very high ransom payments.”
“This is a dangerous and staggering sum of money for one, relatively small group to possess,” researchers said. “For context, this amount is larger than the annual offensive security budget of Canada.”
Source: The Record
(Links and quotes via original reporting)
In the UK, DHL has announced that it is investigating a data breach sourced back to its use of the MOVEit software, which was subsequently exploited by a Russia-based ransomware group, The Record reports.
In a statement to Recorded Future News, DHL confirmed that one of its software providers had been affected by the vulnerability affecting MOVEit, a file-sharing tool from Progress Software.
“Upon being made aware of the incident, DHL quickly launched an investigation working with relevant experts to understand the impacts,” a DHL spokesperson said. “This investigation is ongoing, and we will continue to communicate with those affected when we have more information to share."
The shipping giant is the latest big-name company to announce a breach related to the Clop ransomware gang’s exploitation of the MOVEit bug. Progress Software has patched the software, however, cybercriminals have reportedly continued to find unpatched targets.
Emsisoft researchers have been tracking the number of companies involved. They found that at least 383 organisations have been affected with the information of 20,421,414 people leaked as a result.
A number of organisations reportedly filed documents with regulators in Maine last week confirming that the data that was accessed through MOVEit. Some banks and financial institutions stated that hundreds of thousands of customers were affected while higher-profile organisations confirmed breaches with smaller numbers of victims.
Online poker cardroom PokerStars revealed that its breach involved the Social Security numbers of 110,291 people, while Pennsylvania-based Franklin Mint Federal Credit Union said 140,963 had their Social Security numbers accessed by Clop.
1st Source Bank had the sensitive data of 450,000 customers exposed through its use of MOVEit, it has since provided victims with two years of identity protection services. The majority of impacted organisations have taken similar action.
On July 21, researchers at Coveware released a report stating that the Clop ransomware group may end up earning anywhere from $75 million to $100 million solely from the MOVEit attack, with the sum “coming from just a small handful of victims that succumbed to very high ransom payments.”
“This is a dangerous and staggering sum of money for one, relatively small group to possess,” researchers said. “For context, this amount is larger than the annual offensive security budget of Canada.”
Source: The Record
(Links and quotes via original reporting)