ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Australian iron ore giant Fortescue Metals victimised by the MOVEit Transfer hack

Linked InXFacebook
bookmark_borderSave to Library
Australian iron ore giant Fortescue Metals said it suffered a significant data breach as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.
 
Fortescue Metals is the fourth-largest iron ore producer in the world, holding 87,000 square kilometres of ore-rich land in the Pilbara region of Western Australia. It has more than 11,000 employees worldwide and also mines gold, copper and lithium in multiple countries.The Clop ransomware gang added nine more organisations to its list of MOVEit Transfer victims over the past week, including Fortescue Metals. As of today, more than 350 organisations worldwide have been impacted by the exploitation of vulnerabilities in the commercial file transfer software.
 
 
The ransomware group said it is in possession of confidential data stolen from Fortescue Metals, adding that the cyber attack was “only financial motivated” and that it “does not care anything about politics”.The group, whose ransom demand isn’t known yet, hasn’t published the stolen data and has given the company another chance to meet its ransom demands. “The company doesn’t care about its customers, it ignored their security!!!” Clop added.Acknowledging the ransomware group’s announcement, Fortescue Metals confirmed that on the 28th of May, it became a victim of a “low-impact cyber incident”. The company added that the data exfiltrated from its network “was not confidential in nature,” and that “a small portion of data” was stolen from its network.“We notified the Australian Cyber Security Centre of the incident, and our internal investigation and remediation actions are now complete,” Fortescue said in a statement.Last week, US-based population research service provider Pension Benefit Information said it suffered a massive data breach as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.According to PBI’s internal investigation, the compromised information included clients’ names, partial mailing addresses, Social Security numbers, and dates of birth. The company clarified that this incident did not affect PBI’s “core systems or software”.Initially, in a filing with the office of the Maine Attorney General, PBI said that 371,359 individuals were affected by the data security incident. The company later said in a separate filing with the U.S. Department of Health and Human Services Office for Civil Rights that the incident impacted at least 1,209,825 individuals.
Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543