Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack

Data allegedly stolen from the companies has been made available for download on the Cl0p ransomware leak website.

HMI hacking

Industrial giants Schneider Electric and Emerson have been named by cybercriminals as victims of the recent campaign targeting Oracle E-Business Suite (EBS) instances.

Threat actors, presumably a cluster of the FIN11 profit-driven threat group, have exploited Oracle EBS vulnerabilities to steal data from dozens of organizations, including major companies. 

The hackers have started naming alleged victims on the leak website set up for the Cl0p ransomware, and in some cases they have started releasing data that allegedly originates from the targeted companies. 

Two of those alleged victims are Schneider Electric and Emerson, neither of which has responded to SecurityWeek’s repeated requests for comment. 

The Cl0p leak website contains links to 2.7 TB of archive files storing information allegedly obtained from Emerson and 116 GB of archive files with information allegedly belonging to Schneider Electric. 

SecurityWeek’s investigation, limited to a structural analysis of the leaked file tree and associated metadata, indicates that in both cases the data likely originates from an Oracle environment.

Advertisement. Scroll to continue reading.

Security researcher Dominic Alvieri has independently confirmed that the leaked data was likely obtained as a result of the recent Oracle EBS hack.  

SecurityWeek has reached out to several of the companies listed on the Cl0p leak website and none of them has responded, likely due to their ongoing investigations. 

However, major organizations such as Harvard University, South Africa’s Wits University, and American Airlines subsidiary Envoy Air have publicly confirmed being impacted. 

The threat group that is behind the recent Oracle EBS hack is also believed to have conducted similar campaigns targeting Cleo, MOVEit, and Fortra file transfer products. Each of those operations targeted many organizations and resulted in massive amounts of data being compromised. 

While historical evidence suggests the cybercriminals responsible for the Oracle EBS campaign are unlikely to make false claims of compromise, they, and other profit-driven groups, have been observed exaggerating the sensitivity of the exfiltrated data.

If confirmed, this would not be the first time Schneider Electric and Emerson have been targeted by cybercriminals. 

Roughly one year ago, the Medusa ransomware group claimed to have stolen nearly 1 TB of data from Emerson and demanded a $100,000 ransom. 

Schneider Electric last year confirmed on at least two separate occasions that it had been targeted by cybercriminals.

Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability 

Related: Toys ‘R’ Us Canada Customer Information Leaked Online

Related: Hackers Target Swedish Power Grid Operator

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

MongoDB has appointed Doug Bowers as Chief Information Security Officer.

Ben Wilkens has been promoted to Director of Cybersecurity at NMFTA.

Cato Networks has appointed Meital Koren as Chief Legal Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.