Crown Resorts confirms Clop extortion attempt after GoAnywhere zero-day
- Organization
- Crown Resorts
- Exploit
- Supply Chain Attack
- Industry
- Casinos and Entertainment
Crown Resorts, Australia's largest casino and entertainment operator, confirmed in late March 2023 that it had been contacted by a ransomware group claiming to hold a limited number of company files. The claim traced back to the Clop group's mass exploitation of a zero-day flaw, tracked as CVE-2023-0669, in Fortra's GoAnywhere managed file transfer product.
Crown's head of corporate communications said the company became aware of the incident late in the preceding week, when its information security team intercepted a series of emails from the group. Crown said customer data had not been compromised, citing the way it used the file transfer service, and that its resort, casino and wider business operations were unaffected. It isolated its use of GoAnywhere while it investigated and worked with law enforcement.
Clop had shifted over the previous year from encrypting victims' files to pure data extortion. It claimed to have breached about 130 organisations in a ten day window in early February 2023 and named a further 60 between 22 and 24 March. Other named victims included Rubrik, the City of Toronto, Hitachi Energy, Procter and Gamble and Saks Fifth Avenue.
Fortra issued patches roughly a week after detecting suspicious activity on 30 January 2023. Crown Resorts confirmed on 5 April 2023 that a small number of files had been released on the dark web, including employee time and attendance records and some membership numbers from Crown Sydney. Crown said no personal information of customers had been compromised, and that it was notifying all impacted individuals and updating the membership numbers of those affected as a precaution.