banner Expire 1 July 2024
Ad Ends 13 April 2024
banner Expire 15 July 2024
banner Expire 18 April 2024
ad End 18 October 2024
Ad Ends 13 July 2023
banner Expire 20 May 2024
What's new
Ad expire at 5 May 2024
UniCvv
CrdCrew.cc Carding forum
Western union transfer
banner expire at 21 August

Carding.pw carding forum
adv exp at 23 may

SHELL LATEST TO FALL TO ACCELLION FTA EXPLOITS

ESCO

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,305
Reaction score
710
Points
212
Awards
2
  • Somebody Likes you
  • First post
Shell has become the latest big-name firm to reveal it was affected by a data breach targeting vulnerabilities in legacy file transfer software.

In a brief statement that came to light this week, the oil giant admitted it is a customer of Accellion’s File Transfer Appliance (FTA) product.

It said it had addressed the exploited vulnerabilities and begun an investigation into the incident. As per other organizations breached in this way, it claimed that its core IT system was unaffected as FTA is isolated from the rest of its digital infrastructure.

“The ongoing investigation has shown that an unauthorized party gained access to various files during a limited window of time. Some contained personal data and others included data from Shell companies and some of their stakeholders,” the statement noted.

“Shell is in contact with the impacted individuals and stakeholders and we are working with them to address possible risks. We have also been in contact with relevant regulators and authorities and will continue to do so as the investigation continues.”

It’s unclear when Shell discovered the breach and which vulnerabilities were targeted. Accellion patched two zero-day bugs in late December, but attackers managed to compromise Singtel via a third vulnerability in January.

Other organizations known to have been affected include the New Zealand central bank, aircraft maker Bombardier, retail giant Kroger and legal firm Jones Day.

Security vendor FireEye has claimed that the group behind the attacks share similarities with the FIN11 cybercrime gang and the Clop ransomware group, on whose leaks site information stolen from some of the victims of this campaign has been published.
Accellion itself has claimed that “fewer than 100” of the 300 or so corporate users of FTA were affected by the campaign, and “fewer than 25 appear to have suffered significant data theft.”
 
Ad End 1 July 2024
Top