Cyberattack
Oil or fuel facility
MOVEit exploitation campaign — energy-sector data theft
Beginning 27 May 2023; disclosures in June–July 2023
Global (energy-sector campaign; marker at Shell headquarters, London)
Map
51.5000, -0.1100
What happened
Cl0p exploited a zero-day SQL-injection vulnerability in Progress Software's MOVEit Transfer product, installed the LEMURLOOT web shell and stole data from victim file-transfer databases. Energy-related victims publicly identified included Shell, Siemens Energy and two US Department of Energy entities. Shell said there was no evidence its core IT systems were affected, and no reviewed source reported interruption of refining, generation, drilling or grid operations at the named energy organizations. This is an aggregate supply-chain data-theft record, not a claim that the whole energy sector or operational technology was disabled.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Oil or fuel facility
- Current temperature
- Loading…
- Latitude
- 51.5000°
- Longitude
- -0.1100°
Attribution
Attributed to Cl0p ransomware/extortion group
CISA and the FBI attributed the mass exploitation of CVE-2023-34362 to Cl0p. The campaign primarily stole data from exposed MOVEit servers rather than encrypting or disrupting victims' operational systems.
