Hitachi Energy confirms employee data breach in Clop GoAnywhere campaign

Organization
Hitachi Energy
Exploit
Supply Chain Attack
Industry
Energy Technology

Hitachi Energy, the Zurich headquartered power technology business of Japan's Hitachi with around 40,000 employees in 90 countries, confirmed in mid March 2023 that employee data may have been taken in the Clop ransomware group's campaign against Fortra's GoAnywhere managed file transfer software.

In a statement posted to its website, the company said a third party software provider, Fortra GoAnywhere MFT, had been attacked by Clop and that this "could have resulted in an unauthorized access to employee data in some countries". It added that it had no information indicating that its network operations, or the security and reliability of customer data, had been compromised.

Hitachi Energy said it disconnected the affected third party system, opened its own investigation with outside forensic specialists, informed employees who might be affected and notified applicable data privacy, security and law enforcement authorities.

The campaign exploited CVE-2023-0669, a remote code execution flaw that Fortra disclosed at the start of February 2023 after attacks were already under way, with a patch following about a week later. Clop claimed to have breached more than 130 organisations through the flaw. It listed Hitachi Energy on its leak site on 16 March and threatened to publish the stolen files, with the company issuing its own notice within days.

Sources