logo

Cactus ransomware claim to steal 1.5TB of Schneider Electric data

ID: ca98ceee-4de7-5afb-9dd9-0713d96fea59

STIX ID: report--ca98ceee-4de7-5afb-9dd9-0713d96fea59

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-19

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cactus ransomware claims to have breached Schneider Electric’s Sustainability Business division on January 17, exfiltrating an alleged 1.5 TB of data and publishing a 25 MB sample (including passport scans and NDA documents) on its leak site as proof while extorting the company; the leaked data could expose sensitive customer information related to industrial control and regulatory compliance. The report notes Cactus is a relatively new double-extortion operation that uses purchased credentials, phishing, and vulnerability exploitation to move laterally and steal data, and has added over 100 companies to its leak site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.