Ofcom Latest MOVEit Victim as Exploit Code Released

UK telecommunications regulator Ofcom has become the latest organization to be affected by the Clop extortion campaign targeting a zero-day bug in MOVEit software.

Ofcom confirmed the news in a short statement yesterday. Although the attacker’s own systems were not compromised during the attack, the attacker managed to access information of both the regulated organization and its staff.

For more information on the MOVEit zero-day bug, see Critical Zero-day Flaw Exploited in MOVEit Transfer.

“A limited amount of information (some of which is classified) about certain companies we regulate was downloaded during the attack, along with personal data of 412 Ofcom employees,” Ofcom explained.

“We have taken immediate steps to prevent further use of MOVEit services and implement recommended security measures. We have also promptly alerted all affected Ofcom regulated companies and will continue to We will continue to provide support and assistance to

The news comes after the Irish Health Service (HSE) admitted late last week that it was also affected by a data theft campaign.

“HSE announced yesterday evening (June 8) that our external partner (EY), who is working with us on a project to automate some of our recruitment processes, has announced that MOVEit, the technology product that our external partner (EY) has been using to support this. I am aware that I have been alerted to a cyberattack against

“This analysis found that information was likely accessed on no more than 20 individuals involved in the recruitment process. It consists of positions and more general information about open positions and, importantly, no other personally identifiable or financial data.”

Believed to be affiliated with the Clop ransomware group, the campaign exploited a zero-day vulnerability (CVE-2023-34362) in popular file transfer software to steal data from a number of global companies.

In theory, the likelihood of copycat attacks has increased in recent days since the proof-of-concept exploit was released last Friday. Organizations still running unpatched servers exposed to the Internet are encouraged to update their systems as soon as possible.

Editorial image credit: T. Schneider / Shutterstock.com

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *