Hitachi Energy emerges as victim of Clop gang’s Fortra attack

Skórzewiak – stock.adobe.com

The power and energy division of Japanese conglomerate Hitachi has disclosed that it has fallen victim to a Clop cyber attack, but insists customer data is safe

Alex Scroxton

By

Published: 21 Mar 2023 12:15

Hitachi Energy, the multibillion-dollar power and energy solutions division of Japan’s Hitachi conglomerate, has confirmed that some employee data was accessed by the Clop (aka Cl0p) ransomware cartel in a cyber incident that originated through a vulnerability in Fortra’s managed file transfer product GoAnywhere.

Hitachi did not disclose what data was affected in the incident, or whether or not it has entered into any form of negotiation with the Clop gang, although the cyber criminals have added its details to their dark web leak site, with the implicit threat that they will leak its data soon if it does not cooperate.

“Upon learning of this event, we took immediate action and initiated our own investigation, disconnected the third-party system, and engaged forensic IT experts to help us analyse the nature and scope of the attack,” said a Hitachi spokesperson.

“Employees who may be affected have been informed and we are providing support. We have also notified applicable data privacy, security and law enforcement authorities and we continue to cooperate with the relevant stakeholders.

“According to our latest information, our network operations or security of customer data have not been compromised. We will continue to update relevant parties as the investigation progresses.”

The disclosure means Hitachi Energy joins a growing list of well over 100 victims that Clop claims to have hit through the Fortra GoAnywhere vulnerability.

The vulnerability itself, which is tracked as CVE-2023-0669, enables remote code execution (RCE) within GoAnywhere, and while it was disclosed and patched over a month ago, the Clop operation was able to take advantage of it to compromise a litany of new victims.

Among those to have already come forward is storage and security solutions supplier Rubrik, which has also been listed and threatened on Clop’s leak site.

In the Rubrik incident, the gang appears to have gained access to a limited amount of data held in a non-production IT testing environment and some customer and partner sales data, but not any data that Rubrik secures on behalf of its customers.

Other organisations recently added to Clop’s leak site include fossil fuel giant Shell and aviation manufacturer Bombardier, although it is unclear whether or not they were compromised via the Fortra bug.

Note that Bombardier was previously a Clop victim in 2021, when the gang attacked it via another compromised file transfer application run by Accellion.

Prolific ransomware family

As the number of new (or repeated) victims being named by Clop demonstrates, the gang remains a highly prolific operator despite law enforcement actions, which clipped Clop’s wings in 2021.

The gang has been around for about four years at this point, and as of late 2021 was thought to have made more than half a billion dollars in ransom payments.

The Russian-speaking gang runs on a ransomware-as-a-service basis, meaning it is used by multiple connected affiliates assigned multiple designations by various researchers, perhaps most significantly the group tracked by Google’s Mandiant as FIN11.

The Clop locker first evolved as a variant of the CryptoMix ransomware family, and is so-named because it appends the extension Cl0p to the files it encrypts.

According to Trend Micro, it targets a victim’s entire network rather that individual machines by accessing the Active Directory server prior to execution to determine the system’s Group Policy, which enables it to persist on victim endpoints even after they have supposedly been disinfected.

Although Clop affiliates have become famous for their exploitation of file transfer vulnerabilities, the locker has more usually been observed being distributed as part of a phishing campaign.

Most recently, SentinelOne’s SentinelLabs reported that it had found the first Linux-targeting variant of Clop in the wild. However, at the present time this variant seems to be under development as its executable contains a flawed encryption algorithm which makes decryption a doddle. A decryptor for the Linux variant can be found on GitHub.

Read more on Data breach incident management and recovery

Read More
Blythe Kucera

Latest

College Football Offseason Buzz: Tom Moore Returns to Iowa as Senior Consultant

This is college football. At some point, the games pause, but the news and drama never does. Here's an offseason tracker for buzz across the college football landscape, including coaching changes, injury news, personnel moves and more. Tom Moore Returns to Iowa at 87 as senior consultant The Iowa Hawkeyes  announced the hiring of former

Football Is Life: ‘Ted Lasso’ Star Cristo Fernandez Lands Deal With USL Club

Forward Cristo Fernandez, the actor who portrayed Dani Rojas on the Apple TV series "Ted Lasso" has signed with El Paso Locomotive FC of the USL Championship to play soccer professionally. Terms of the deal announced Tuesday, which still must be approved by the second-tier league and soccer federation, were not disclosed. Fernandez earned the

The quiet grit of Cowboys legend Craig Morton

The Dallas Cowboys family and the football world lost a true pioneer this past Sunday with the passing of Craig Morton. As one of the original cornerstones of the franchise, Morton helped transform the Cowboys from a young expansion team into a perennial powerhouse. He carried himself with a quiet dignity and a toughness that

College Football’s No. 10 TE Recruit Set to Visit Three Elite Programs

One of the top-flight prospects coming out of the state of Ohio and among the best targets in the 2027 college football recruiting class is poised to take some consequential visits to national programs in the weeks to come, but the Buckeyes notably aren’t among them. Four-star Columbus (Ohio) Francis DeSales national No. 10 ranked

Newsletter

Don't miss

College Football Offseason Buzz: Tom Moore Returns to Iowa as Senior Consultant

This is college football. At some point, the games pause, but the news and drama never does. Here's an offseason tracker for buzz across the college football landscape, including coaching changes, injury news, personnel moves and more. Tom Moore Returns to Iowa at 87 as senior consultant The Iowa Hawkeyes  announced the hiring of former

Football Is Life: ‘Ted Lasso’ Star Cristo Fernandez Lands Deal With USL Club

Forward Cristo Fernandez, the actor who portrayed Dani Rojas on the Apple TV series "Ted Lasso" has signed with El Paso Locomotive FC of the USL Championship to play soccer professionally. Terms of the deal announced Tuesday, which still must be approved by the second-tier league and soccer federation, were not disclosed. Fernandez earned the

The quiet grit of Cowboys legend Craig Morton

The Dallas Cowboys family and the football world lost a true pioneer this past Sunday with the passing of Craig Morton. As one of the original cornerstones of the franchise, Morton helped transform the Cowboys from a young expansion team into a perennial powerhouse. He carried himself with a quiet dignity and a toughness that

College Football’s No. 10 TE Recruit Set to Visit Three Elite Programs

One of the top-flight prospects coming out of the state of Ohio and among the best targets in the 2027 college football recruiting class is poised to take some consequential visits to national programs in the weeks to come, but the Buckeyes notably aren’t among them. Four-star Columbus (Ohio) Francis DeSales national No. 10 ranked

Playson builds on strong growth in Switzerland with StarVegas partnership

Playson, the accomplished digital entertainment supplier, has further solidified its footprint in the regulated Swiss market by entering a strategic partnership with StarVegas, one of the country’s first licensed online casino operators. StarVegas is a leading Swiss online casino brand operated by Casino Interlaken, one of the country’s most established land-based casino groups. It is

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand

Getting a business loan now comes with a frequent flyer upside

Australian fintech Prospa has partnered with Qantas Business Rewards, letting eligible SMEs earn up to 500,000 points per loan. What’s happening: Australian fintech lender Prospa has partnered with Qantas Business Rewards to allow eligible small and medium business owners to earn up to 500,000 Qantas Points per loan when taking out a Prospa Small Business