Ad End 1 August 2025
Ad Ends 13 July 2025
ad End 25 October 2025
Ad Ends 20 April 2025
Ad expire at 5 August 2024
banner Expire 9 June 2025
banner Expire 25 October 2025
banner Expire 10 May 2025
What's new
Wizard's shop 2.0
Money Club cc shop
banner Expire 15 January 2025
banner Expire 20 October 2024
UniCvv
Yale Lodge
Kfc CLub
adv exp at 30 July 2025
Carding.pw carding forum
BidenCash Shop

SHELL LATEST TO FALL TO ACCELLION FTA EXPLOITS

Dark_Code_x

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 28, 2020
Messages
6,775
Reaction score
726
Points
212
Awards
2
  • Somebody Likes you
  • First post
Shell has become the latest big-name firm to reveal it was affected by a data breach targeting vulnerabilities in legacy file transfer software.

In a brief statement that came to light this week, the oil giant admitted it is a customer of Accellion’s File Transfer Appliance (FTA) product.

It said it had addressed the exploited vulnerabilities and begun an investigation into the incident. As per other organizations breached in this way, it claimed that its core IT system was unaffected as FTA is isolated from the rest of its digital infrastructure.

“The ongoing investigation has shown that an unauthorized party gained access to various files during a limited window of time. Some contained personal data and others included data from Shell companies and some of their stakeholders,” the statement noted.

“Shell is in contact with the impacted individuals and stakeholders and we are working with them to address possible risks. We have also been in contact with relevant regulators and authorities and will continue to do so as the investigation continues.”

It’s unclear when Shell discovered the breach and which vulnerabilities were targeted. Accellion patched two zero-day bugs in late December, but attackers managed to compromise Singtel via a third vulnerability in January.

Other organizations known to have been affected include the New Zealand central bank, aircraft maker Bombardier, retail giant Kroger and legal firm Jones Day.

Security vendor FireEye has claimed that the group behind the attacks share similarities with the FIN11 cybercrime gang and the Clop ransomware group, on whose leaks site information stolen from some of the victims of this campaign has been published.
Accellion itself has claimed that “fewer than 100” of the 300 or so corporate users of FTA were affected by the campaign, and “fewer than 25 appear to have suffered significant data theft.”
 
Ad End 1 February 2024
Top