Shell says BG Group Australia employee data taken in MOVEit breach
- Organization
- Shell (BG Group Australia)
- Exploit
- Supply Chain Attack
- Industry
- Oil and Gas
Shell disclosed in September 2023 that personal information belonging to people who had worked for BG Group in Australia was accessed without authorisation through the MOVEit Transfer file transfer software. Shell completed its acquisition of BG Group in 2016, and the affected records predated the merger.
The company said the exposed data dated from 2013. It described the material only as personal information relating to BG Group employees, adding that although the information was historic and some of it might be out of date, affected individuals still faced a risk of identity theft and of being targeted by phishing campaigns.
Shell did not respond to a Reuters request for comment seeking the exact number of individuals affected. The company said it had identified the individuals concerned and made attempts to notify them, with contact beginning in early July 2023.
The incident stemmed from mass exploitation of a MOVEit Transfer vulnerability in May 2023, attributed to the Clop extortion group. Shell had confirmed in July 2023 that MOVEit Transfer was used by a small number of its employees and customers, that the event was not a ransomware attack on Shell, and that there was no evidence of impact to other Shell IT systems. Estimates of the campaign's overall reach varied over time, from more than 200 organisations in July to more than a thousand businesses by September.
Sources
- Insurance Journal (Reuters), Shell Says Australian Unit BG Group Hit by MOVEit Cybersecurity Breach
- Cyber Daily, Shell employee data breached as part of MOVEit hack
- The Canberra Times, Shell's Australian BG Group business hit by MOVEit hack
- iTnews, Shell's BG Group hit by MOVEit cybersecurity breach