logo

'Cactus' Ransomware Strikes Schneider Electric

ID: 51abda93-b05a-5f9d-bfb7-2f90ce5467ba

STIX ID: report--51abda93-b05a-5f9d-bfb7-2f90ce5467ba

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-30

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Schneider Electric reported a January 17 cyberattack limited to its Sustainability Business division—impacting the Resource Advisor platform—and media/analysts have attributed the incident to the Cactus ransomware group; Schneider states the incident was isolated from safety-critical systems and expected business recovery by Jan. 31. The report profiles Cactus as a prolific, young ransomware actor that leverages known vulnerabilities (notably Fortinet VPN flaws) and common tooling (network scanners, PowerShell) for initial access and lateral movement, and flags potential customer data exposure across many affected clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.