Software maker Fortra told enterprise customers that their data was safe even if it wasn’t, following a ransomware attack on their systems, TechCrunch has revealed.
As we’ve been reporting, the Clop ransomware gang exploited a newly discovered bug in Fortra’s GoAnywhere file transfer software. This bug is used by thousands of organizations to transfer sensitive data over the Internet. This bug allowed ransomware gangs to hack into his January 31st and carry out a massive ransomware attack. The Clop gang, which has ties to Russia, claimed to have compromised about 130 organizations that were using his vulnerable GoAnywhere tool at the time of the ransomware attack.
Now a new victim is coming to light.
Consumer goods giant Procter & Gamble confirmed to TechCrunch that the company was “one of many companies affected by Fortra’s GoAnywhere incident,” which resulted in hackers obtaining employee information. rice field. Health care and wellness program provider US Wellness also revealed this week that a third-party breach may have compromised consumer personal information and protected health data. TechCrunch learned that US Wellness was a GoAnywhere customer at the time of the ransomware attack.
As the number of victims grows, more details are beginning to emerge about how Fortra handled the incident.
TechCrunch has spoken to two victim organizations who learned that data had been stolen from their GoAnywhere systems after receiving a ransom demand. Both organizations were previously informed by Fortra that their data was unaffected by the ransomware attack.
One of the organizations told TechCrunch that they realized the situation had changed when they were contacted by the alleged hacker, but said the organization had not entered into negotiations or paid the ransom demand. .
When asked about this by email, Fortra spokesperson Rachel Woodford declined to comment, but two organizations told us, or that Fortra told customers their data was safe. Fortra did not allow CISO Chris Reffkin to be interviewed.
The full impact of the massive hack resulting from the GoAnywhere vulnerability remains unknown. Fortra did not disclose whether his internal GoAnywhere system, which stores customer data, was compromised during the ransomware attack, despite repeated requests from TechCrunch.
The Clop ransomware gang has added dozens of new victims to its dark web leak site over the past few days. This includes payment software startup AvidXchange, investment giant His Onex, the UK Pension Protection Fund and the City of Toronto. All of which have been identified. TechCrunch reports that the organization was using vulnerable GoAnywhere file transfer software at the time of the breach, as well as dozens of others.
It follows other additions to the leak page, including Colombian energy giant Grupo Vanti, Australian gambling giant Crown Resorts and Medex Healthcare.
Fortra has yet to formally confirm the January breach, only releasing an inaccessible advisory on its website. His latest Fortra press release on March 16 announced that the company had been awarded “Best Cybersecurity Company” from his Cyber security Excellence Awards.