Hitachi Energy confirms employee data breach in Clop GoAnywhere campaign
- Organization
- Hitachi Energy
- Exploit
- Supply Chain Attack
- Industry
- Energy Technology
Hitachi Energy, the Zurich headquartered power technology business of Japan's Hitachi with around 40,000 employees in 90 countries, confirmed in mid March 2023 that employee data may have been taken in the Clop ransomware group's campaign against Fortra's GoAnywhere managed file transfer software.
In a statement posted to its website, the company said a third party software provider, Fortra GoAnywhere MFT, had been attacked by Clop and that this "could have resulted in an unauthorized access to employee data in some countries". It added that it had no information indicating that its network operations, or the security and reliability of customer data, had been compromised.
Hitachi Energy said it disconnected the affected third party system, opened its own investigation with outside forensic specialists, informed employees who might be affected and notified applicable data privacy, security and law enforcement authorities.
The campaign exploited CVE-2023-0669, a remote code execution flaw that Fortra disclosed at the start of February 2023 after attacks were already under way, with a patch following about a week later. Clop claimed to have breached more than 130 organisations through the flaw. It listed Hitachi Energy on its leak site on 16 March and threatened to publish the stolen files, with the company issuing its own notice within days.
Sources
- Hitachi Energy, Third-party cybersecurity incident
- BleepingComputer, Hitachi Energy confirms data breach after Clop GoAnywhere attacks
- SecurityWeek, Hitachi Energy Blames Data Breach on Zero-Day as Ransomware Gang Threatens Firm
- Security Affairs, Hitachi Energy breached by Clop gang through GoAnywhere Zero-Day exploitation
- Hitachi Energy, Hitachi Energy rated among top 5 of most sustainable companies