{"id":25532,"date":"2023-06-21T07:43:09","date_gmt":"2023-06-21T11:43:09","guid":{"rendered":"http:\/\/worldjusticenews.com\/news\/?p=25532"},"modified":"2023-06-21T07:43:09","modified_gmt":"2023-06-21T11:43:09","slug":"moveit-hack-gang-claims-not-to-have-bbc-ba-and-boots-data","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2023\/06\/21\/moveit-hack-gang-claims-not-to-have-bbc-ba-and-boots-data\/","title":{"rendered":"MOVEit hack: Gang claims not to have BBC, BA and Boots data"},"content":{"rendered":"<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\"><b class=\"ssrcss-hmf8ql-BoldText e5tfeyi3\">Cyber- criminals have told the BBC they do not have data belonging to large UK organisations thought to be victims of a mass hack.<\/b><\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Firms including the BBC, British Airways and Boots have told staff that sensitive payroll data was stolen in last month&#8217;s breach.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But now the hackers Clop, speaking over email, claim &#8220;we don&#8217;t have that data&#8221;.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">It raises the possibility that another unknown hacking gang has the stolen data or that Clop is lying.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Zellis, the UK payroll provider that hackers breached to gain access to the BBC, Boots and BA&#8217;s data, said it could not comment as a police investigation was ongoing.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Since 14 June, Clop has been posting company profiles of victims of its hack to pressure them into paying a ransom.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But none of the UK&#8217;s largest and most well-known victims&#8217; names has been posted so far.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">In small batches Clop has added the names, websites and company addresses of nearly 50 victims to its darknet website.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The organisations include banks, universities, travel firms and software companies from more than a dozen different countries including the US, Germany, Switzerland, the UK, Canada and Belgium.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Some of the companies listed by Clop on their so-called &#8220;leak site&#8221; have separately confirmed that they have had data stolen.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Clop is threatening to publish the stolen data unless victims pay a ransom which is likely to be hundreds of thousands of dollars or more in Bitcoin.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-19w8cxh-ComponentWrapper-HeadlineComponentWrapper egtrm1f0\" data-component=\"subheadline-block\">\n<h2 id=\"We-dont-have-that-data\" class=\"ssrcss-y2fd7s-StyledHeading e1fj1fc10\" tabindex=\"-1\"><span role=\"text\">&#8216;We don&#8217;t have that data&#8217;<\/span><\/h2>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">It is thought hundreds of organisations who used the file transfer tool MOVEit have had their data stolen.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">That included eight big UK organisations &#8211; among them the BBC, BA and Boots &#8211; who were customers of Zellis which was itself breached through MOVEit.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But in an email exchange with the BBC the cyber-criminals repeatedly claimed not to have stolen the Zellis data.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">&#8220;We don&#8217;t have that data and we told Zellis about it. We just don&#8217;t have it. We are an old group and have never deceived anyone, if we say that we do not have information, then we do not have it,&#8221; the hackers claimed.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Zellis would only refer us to its previous statement, which said: &#8220;We can confirm that a small number of our customers have been impacted by this global issue and we are actively working to support them.&#8221;<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The company says that as soon as it became aware of the hack it took immediate action and disconnected the computer server on which the MOVEit software was installed.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The firm says it has brought in an expert external security team to help it respond to the attack and has notified the relevant UK data authorities.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-19w8cxh-ComponentWrapper-HeadlineComponentWrapper egtrm1f0\" data-component=\"subheadline-block\">\n<h2 id=\"Multiple-possibilities\" class=\"ssrcss-y2fd7s-StyledHeading e1fj1fc10\" tabindex=\"-1\"><span role=\"text\">Multiple possibilities<\/span><\/h2>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Cyber-security experts are puzzled by Clop&#8217;s claims which further muddy an already complex situation.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Threat researcher Brett Callow, from Emsisoft, said Clop could be covering up the fact it stole the data as part of a sale deal with another hacking group.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But Clop claimed &#8220;we didn&#8217;t sell anything to other hackers&#8221;.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Other experts say there are many possibilities.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">&#8220;Clop has no real reason to say they don&#8217;t have the data,&#8221; said SOS Intelligence boss Amir Had\u017eipasi\u0107 .<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">&#8220;If they are telling the truth then it makes me think that some other hackers may have got in and stolen the data before Clop and if Clop don&#8217;t have the data then this situation is less predictable. The files are going to end up somewhere on the darkweb via another hacking group,&#8221; he added.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The hack was first announced on 31 May by Progress Software, the makers of MOVEit.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The criminals found a way to break into MOVEit and were then able to use that access to get into the databases of potentially hundreds of other companies.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Since the initial MOVEit disclosure, however, researchers have found many security issues within the software which means it is possible that the data was stolen in a different way by a different group.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">On Friday, the US\u00a0<a class=\"ssrcss-k17ofw-InlineLink e1no5rhv0\" href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-and-fbi-release-advisory-cl0p-ransomware-gang-exploiting-moveit-vulnerability\" target=\"_blank\" rel=\"noopener\">announced a $10m reward<\/a>\u00a0for &#8220;information linking the Clop gang or any other malicious cyber -ctors targeting US critical infrastructure to a foreign government&#8221;.<\/p>\n<p>Source: <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-65965453\" target=\"_blank\" rel=\"noopener\">bbc.co.uk<\/a><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">Cyber- criminals have told the BBC they do not have data belonging to large UK organisations thought to be victims of a mass hack. Firms including the BBC, British Airways and Boots have told staff <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2023\/06\/21\/moveit-hack-gang-claims-not-to-have-bbc-ba-and-boots-data\/\" title=\"MOVEit hack: Gang claims not to have BBC, BA and Boots data\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":25533,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[2,4],"tags":[2144,9502,5507,9501,9528,7572,7120,9527],"class_list":{"0":"post-25532","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-uk","9":"tag-bbc","10":"tag-boots","11":"tag-british-airways","12":"tag-clop","13":"tag-computer-hacking","14":"tag-cyber-attacks","15":"tag-cyber-security","16":"tag-moveit","17":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/25532","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=25532"}],"version-history":[{"count":2,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/25532\/revisions"}],"predecessor-version":[{"id":25535,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/25532\/revisions\/25535"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/25533"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=25532"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=25532"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=25532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}