ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Siemens Energy and Schneider Electric victimised by MOVEit Transfer hack

Global energy giant Siemens Energy suffered a cyber incident as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.Earlier this month, US company Progress Software said that threat actors found a way to exploit a zero-day SQL vulnerability in the Moveit Transfer web application. This enabled the hackers to exfiltrate data from the web application.The Clop ransomware group, which claimed responsibility for the global cyber security incident, recently listed Siemens Energy in its list of victims along with hundreds of other organisations. 
 
Acknowledging the ransomware group’s claims, a company spokesperson said that it was indeed breached as a result of hackers exploiting the MOVEit Transfer zero-day vulnerability, but critical data wasn’t impacted.In a statement shared with the media, Siemens Energy said, “Regarding the global data security incident, Siemens Energy is among the targets. Based on the current analysis no critical data has been compromised and our operations have not been affected. We took immediate action when we learned about the incident.”The spokesperson said Siemens Energy is in the process of determining the impact of the security incident, adding that the vulnerable MOVEit application was used in a “limited deployment” across its network.Another energy management and automation company, Schneider Electric, recently said that it was also a victim of hackers exploiting a zero-day vulnerability in the MOVEit Transfer web application.“On May 30th, 2023, Schneider Electric became aware of vulnerabilities impacting Progress MOVEit Transfer software. We promptly deployed available mitigations to secure data and infrastructure and have continued to monitor the situation closely.“Subsequently, on June 26th, 2023, Schneider Electric was made aware of a claim mentioning that we have been the victim of a cyber-attack relative to MOVEit vulnerabilities. Our cybersecurity team is currently investigating this claim as well,” the company said.Earlier this month, Oil and gas giant Shell disclosed that it was also affected by the global security breach orchestrated by the Clop ransomware gang who exploited the zero-day vulnerability in the MOVEit file transfer tool.Other organisations affected by the breach include the BBC, British Airways, drug retailer Boots, Ofcom, and many more. The Louisiana Office of Motor Vehicles (OMV) and the Oregon Department of Transportation (ODOT) also said that they suffered data breaches as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543