Cactus ransomware claim to steal 1.5TB of Schneider Electric data
ID: ca98ceee-4de7-5afb-9dd9-0713d96fea59
STIX ID: report--ca98ceee-4de7-5afb-9dd9-0713d96fea59
Feed Name: Bleeping Computer
Cactus ransomware claims to have breached Schneider Electric’s Sustainability Business division on January 17, exfiltrating an alleged 1.5 TB of data and publishing a 25 MB sample (including passport scans and NDA documents) on its leak site as proof while extorting the company; the leaked data could expose sensitive customer information related to industrial control and regulatory compliance. The report notes Cactus is a relatively new double-extortion operation that uses purchased credentials, phishing, and vulnerability exploitation to move laterally and steal data, and has added over 100 companies to its leak site.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
