Cl0p attacks Schneider Electric

Incident Date: Aug 21, 2023

Attack Overview
VICTIM
Schneider Electric
INDUSTRY
Energy, Utilities & Waste
LOCATION
France
ATTACKER
Clop
FIRST REPORTED
August 21, 2023

The Cl0p Ransomware Gang's Attack on Schneider Electric

The Cl0p ransomware gang has attacked Schneider Electric. Schneider Electric is a multinational company that specializes in energy management and automation solutions. It was founded in 1836 by Adolphe Schneider and his brother Eugène Schneider and is headquartered in Rueil-Malmaison, France. Schneider Electric is a global leader in providing products, software, and services that help individuals and organizations manage energy consumption, enhance efficiency, and automate processes across various industries.

Cl0p posted Schneider Electric to its data leak site on August 21st but provided no further details. Cl0p is a RaaS (Ransomware-as-a-Service) platform first observed in 2019. Cl0p has advanced anti-analysis capabilities and anti-virtual machine analysis to prevent investigations in an emulated environment like those commonly used by security tools. Cl0p is increasingly using automation to exploit known vulnerabilities to infiltrate targets, as well as a SQL injection zero-day vulnerability (CVE-2023-34362) that installs a web shell – a rarity amongst ransomware operators.

Surge in Cl0p Ransomware Attacks

Attacks by Cl0p surged in Q1 of 2023 as the gang leveraged patchable exploits for the GoAnywhere file transfer software to compromise more than 100 victims in a matter of weeks, although it is unknown how well they were able to monetize the attacks. Cl0p is likely to be leveraging automation to identify exposed organizations who have not patched against known vulnerability, which is why we are seeing so many new victims.

Ransom Demands and Future Outlook

Ransom demands vary depending on the target and average around $3 million dollars but have been reported as to be as high as $20 million. Ransom amounts are likely to continue to grow as Cl0p focuses more on the exfiltration of sensitive data.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.