Hitachi Energy disclosed a data breach Friday which occurred after the Cl0p ransomware gang targeted a zero-day vulnerability in Fortra’s GoAnywhere managed file transfer (MFT). The data breach allowed for unauthorized access to employees’ data in some countries:
Upon learning of this event, we took immediate action and initiated our own investigation, disconnected the third-party system, and engaged forensic IT experts to help us analyze the nature and scope of the attack. Employees who may be affected have been informed and we are providing support. We have also notified applicable data privacy, security and law enforcement authorities and we continue to cooperate with the relevant stakeholders.
According to our latest information, our network operations or security of customer data have not been compromised. We will continue to update relevant parties as the investigation progresses.
Sylvain Cortes, VP of Strategy, Hackuity had this to say:
“There are 198,000 known CVEs, and this ransomware gang just needed one to compromise Hitachi’s employee data. The scariest part? They didn’t even have to breach Hitachi’s internal systems. While the victim has since disconnected the compromised third party, this is yet another wake-up call: organizations’ attack surfaces extend far beyond the “surface”. Vulnerability Management has never needed reinventing more than in 2023.”
I have a feeling that there’s more to come from this breach disclosure. I’d not only recommend watching this space, but companies need to learn from this event so that they don’t become the next victim.
Related
This entry was posted on March 21, 2023 at 8:56 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Hitachi Energy Discloses Data Breach
Hitachi Energy disclosed a data breach Friday which occurred after the Cl0p ransomware gang targeted a zero-day vulnerability in Fortra’s GoAnywhere managed file transfer (MFT). The data breach allowed for unauthorized access to employees’ data in some countries:
Upon learning of this event, we took immediate action and initiated our own investigation, disconnected the third-party system, and engaged forensic IT experts to help us analyze the nature and scope of the attack. Employees who may be affected have been informed and we are providing support. We have also notified applicable data privacy, security and law enforcement authorities and we continue to cooperate with the relevant stakeholders.
According to our latest information, our network operations or security of customer data have not been compromised. We will continue to update relevant parties as the investigation progresses.
Sylvain Cortes, VP of Strategy, Hackuity had this to say:
“There are 198,000 known CVEs, and this ransomware gang just needed one to compromise Hitachi’s employee data. The scariest part? They didn’t even have to breach Hitachi’s internal systems. While the victim has since disconnected the compromised third party, this is yet another wake-up call: organizations’ attack surfaces extend far beyond the “surface”. Vulnerability Management has never needed reinventing more than in 2023.”
I have a feeling that there’s more to come from this breach disclosure. I’d not only recommend watching this space, but companies need to learn from this event so that they don’t become the next victim.
Share this:
Like this:
Related
This entry was posted on March 21, 2023 at 8:56 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.