
Hitachi Energy, a subsidiary of the Japanese tech giant which owns power grids and wind farms and offers energy solutions in more than 140 countries, joined the group of victims recently hit by the Clop ransomware group, exploiting a zero-day vulnerability in Fortra’s widely used managed file transfer software, GoAnywhere MFT.
The company confirmed that the Clop ransomware group exploited a flaw in GoAnywhere, potentially allowing unauthorized access to employee data in some countries. Dominic Alvieri, a cybersecurity analyst and security researcher, discovered the breach first.
When the company learned of the attack, it immediately disconnected the third-party system and hired forensic IT experts to investigate the nature and scope of the attack, according to a data breach notification letter. A preliminary investigation revealed that neither network operations nor customer data security had been jeopardized.
The company also stated that it is notifying affected employees and has notified relevant data privacy, security, and law enforcement authorities.
The GoAnywhere MFT vulnerability is a pre-authentication remote code execution flaw, which allows attackers to exploit the flaw and remotely execute the code of their choice without having to authenticate in the GoAnywhere MFT administrative console. The administrative console must be accessible online for the attack to succeed.
The US Cybersecurity and Infrastructure Security Agency and other federal agencies have urged all GoAnywhere MFT users to upgrade their software or use workarounds to mitigate the vulnerability as soon as possible.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543