Cyberattack

Oil or fuel facility

MOVEit exploitation campaign — energy-sector data theft

Beginning 27 May 2023; disclosures in June–July 2023

Global (energy-sector campaign; marker at Shell headquarters, London)

51.5000, -0.1100

Loading free detailed map…

What happened

Cl0p exploited a zero-day SQL-injection vulnerability in Progress Software's MOVEit Transfer product, installed the LEMURLOOT web shell and stole data from victim file-transfer databases. Energy-related victims publicly identified included Shell, Siemens Energy and two US Department of Energy entities. Shell said there was no evidence its core IT systems were affected, and no reviewed source reported interruption of refining, generation, drilling or grid operations at the named energy organizations. This is an aggregate supply-chain data-theft record, not a claim that the whole energy sector or operational technology was disabled.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Oil or fuel facility
Current temperature
Loading…
Latitude
51.5000°
Longitude
-0.1100°

Attribution

Attributed to Cl0p ransomware/extortion group

CISA and the FBI attributed the mass exploitation of CVE-2023-34362 to Cl0p. The campaign primarily stole data from exposed MOVEit servers rather than encrypting or disrupting victims' operational systems.

Sources

  1. #StopRansomware: CL0P exploits MOVEit vulnerabilityCISA and FBI · Incident reporting
  2. Shell confirms it was impacted by Clop's MOVEit attacksRecorded Future News · Shell confirmation and lack of core-IT impact