Schneider Electric, a world leader in industrial manufacturing, has fallen victim to a cyber attack affecting its Sustainability Business division. The attack has been attributed to a rising ransomware operation called “Cactus,” a relatively young but prolific group. The attack was limited to Schneider’s sustainability division, which provides software and consulting services to enterprises, and affected no safety-critical systems. However, the company faces potential repercussions if clients’ business data is leaked. Schneider Electric has not yet revealed the scope of the data that may have been lost, but one affected platform is Resource Advisor, which helps organizations track and manage their ESG, energy, and sustainability-related data. The Cactus ransomware gang has claimed responsibility for the attack, though Schneider Electric has not confirmed this attribution. Cactus is a relatively new ransomware group that relies on known vulnerabilities and off-the-shelf software for its attacks. Schneider Sustainability serves a broad range of organizations across more than 100 countries, including 30% of the Fortune 500. The company has already informed affected customers and expects business operations to return to normal soon. However, the incident highlights the risk posed by basic vulnerabilities, even among organizations with substantial cybersecurity budgets.
Schneider Electric faces ‘Cactus’ Ransomware
Latest from Blog
US and allies accuse North Korean hackers of military espionage
TLDR: North Korean hackers, known as Anadriel or APT45, are stealing military secrets to support their nuclear weapons program. They have targeted defense and engineering firms, as well as NASA and U.S.
ECB tests banks’ cyber security, finds room for improvement
TLDR: Yahoo is part of the Yahoo family of brands. They use cookies for various purposes such as providing sites and applications, authentication, security measures, and measuring usage. Yahoo, as part of
US charges North Korean hacker for hospital ransomware attacks
TLDR: The U.S. DoJ indicted a North Korean hacker for ransomware attacks on hospitals The hacker, Rim Jong Hyok, is part of a group called Andariel and is accused of laundering ransom
Deadline approaching for Cyber Security Framework adoption and mandatory reporting Regulator shifts focus to enforcement from education
TLDR: Key points: Important compliance dates approaching for critical infrastructure assets under the Security of Critical Infrastructure Act. Responsible entities must adhere to specific cyber security frameworks and submit mandatory annual reports.
Cyberattack hits Selenium Grid for Crypto Mining – stay safe
Ongoing Cyberattack Targets Exposed Selenium Grid Services TLDR: Cyberattack targeting older versions of Selenium for crypto mining Threat actors using Selenium Grid services for illicit activities Cybersecurity researchers are warning about an
Bridging the cyber talent gap: tips for CISOs
TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies
Deepfake dangers prompt urgent cybersecurity reevaluations for businesses
TLDR: AI-generated deepfake attacks are on the rise, leading companies to reassess their cybersecurity measures. Companies are developing deepfake response plans and running simulations to increase preparedness. Biometric authentication, once considered secure,
North Korean faces charges for cyberattacks on US targets
TLDR: A North Korean military intelligence operative has been indicted for orchestrating cyberattacks on U.S. hospitals, NASA, and military bases. Rim Jong Hyok, a member of the Andariel Unit, faces charges of
Analysts predict cybersecurity stocks will soar after CrowdStrike’s outage
“`html TLDR: CrowdStrike outage led to potential gains for cybersecurity rivals SentinelOne, Palo Alto Networks, and Microsoft’s cybersecurity business could benefit After a defective CrowdStrike update caused a global tech outage, analysts
Bitsight’s Trust Management Hub: Revolutionizing Security Assessment Process
TLDR: Bitsight has released Trust Management Hub to streamline security assessments. The new solution reduces workload by 25% and improves the assessment cycle by 85%, helping teams close deals faster. Bitsight, a