AI DevwWrld CyberDSA Chatbot Summit Cyber Revolution Summit CYSEC Global Cyber Security & Cloud Expo World Series Digital Identity & Authentication Summit Asian Integrated Resort Expo Middle East Low Code No Code Summit TimeAI Summit

Ransomware Clop affects the main global legal companies: the risk is massive data theft

Linked to Clop, attackers exploited MOVEit software vulnerabilities, strike during Memorial Day holiday

Trecenti società globali, tra cui le tre più grandi ditte legali americane, sono state colpite dal gruppo di hacker noto con il nome Clop, attraverso una vulnerabilità nel software MOVEit, utilizzato per il trasferimento di file. L'attacco, avvenuto nel weekend del Memorial Day, potrebbe aver messo a rischio le informazioni di 16 milioni di persone. Gli hacker, collegati alla Russia, richiedono generalmente milioni di dollari come riscatto.

This pill is also available in Italian language

Thousands of client files of the country's three largest law firms could be at risk as a result of massive global data theft. Kirkland & Ellis, K&L Gates and Proskauer Rose are among the targets, along with fifty other multinational corporations attacked last month. Ransomware group Clop has claimed responsibility for the hack.

A vulnerable software behind the attack

Legal companies have been exposed due to a vulnerability in the MOVEit software used for file transfer. The perpetrators of the attack, who sign as "Lance Tempest", are connected to Clop, also known as TA505. The software attack occurred over Memorial Day weekend.

Holiday attacks and ransom demand in the millions

According to information gathered by Bleeping Computer, a cybersecurity and technology news site, attacks during holiday periods are a defining feature of the Clop group. Cypfer, a team specializing in internet ransomware trading, reported that the allegedly Russia-linked gang usually demands millions in exchange for digital conflict resolution. Last month, the US State Department placed a $10 million bounty on the head of the group, seeking information that could link the group to a foreign government.

The attack has a global impact

Possible 16 million people could be involved in the breach, as suggested by the recent tweet by cybersecurity expert, Brett Callow. In addition to law firms, the attack affected universities, banks and insurance companies around the world, Callow reported. Requests for comment sent to the law firms' New York offices went unanswered Saturday.

Follow us on Telegram for more pills like this

07/08/2023 20:58

Editorial AI

Complementary pills

Clop: new increase in criminal activity on the dark webRecent developments in the group's tactics: infiltration, extortion and prevention strategies

Russian group Clop attacks US government agenciesThe Clop emerges as a possible leading actor. The group, active since 2018, targets organizations affected by a specific vulnerability

US federal agencies in the crosshairs of a global cyberattackA sophisticated cyber-attack exploits software vulnerabilities, targeting critical infrastructure and causing national security concerns

SQL injection vulnerability affects MOVEit Transfer: A security appealProgress software confirms a serious risk for organizations. Researchers and security professionals investigate the impact of the incident

Last pills

Serious vulnerability discovered in Rabbit R1: all user data at riskVulnerability in Rabbit R1 exposes sensitive API keys. What are the privacy risks?

Cyber attack in Indonesia: the new Brain Cipher ransomware brings services to their kneesNew ransomware hits Indonesia: learn how Brain Cipher crippled essential services and the techniques used by hackers

Patelco Credit Union: security incident halts customer services in CaliforniaService disruption and customer frustration: Patelco Credit Union works to resolve security incident

Cyber attack on TeamViewer: immediate response and investigations underwayStrengthened security measures and international collaborations to counter the cyber threat