Cactus ransomware hit Schneider Electric's Sustainability Business division
- Organization
- Schneider Electric
- Exploit
- Ransomware
- Industry
- Energy Management
Schneider Electric, the France-based energy management and automation group, confirmed in late January 2024 that its Sustainability Business division had been hit by a ransomware attack. The company said the incident began on January 17, 2024.
The attack disrupted the division's EcoStruxure Resource Advisor platform, a cloud service used by more than 2,000 organizations to track energy and sustainability data, along with other systems specific to that division. Schneider Electric said the Sustainability Business runs its own isolated network infrastructure and that no other entity in the group was affected.
The Cactus ransomware operation claimed responsibility and said it had taken terabytes of corporate data, a figure reported elsewhere as roughly 1.5TB. Schneider Electric acknowledged that data had been accessed and said it was contacting affected customers directly. The company engaged outside cybersecurity firms to investigate and said it expected to restore the division's platforms within days. Access to the affected business platforms was reported restored on January 31, 2024.
As of the reporting date the company had not said whether a ransom was demanded or paid, and the volume of stolen data rested on the attackers' own claim rather than any independent verification. Cactus, which first appeared in March 2023, is known for double extortion and for gaining initial access through internet-facing VPN appliances before deploying legitimate remote access tools.