Clop Shears GE and Philips: Big Flock Energy, Zero Actual Security
Oh good. Another Tuesday.
So the Clop ransomware crew, which at this point is basically just a standing appointment on my calendar between "coffee goes cold" and "new ticket from Karen in Accounting," has apparently waltzed through the pastures of General Electric and Philips and helped themselves to whatever data was just lying around in the field.
Both companies are currently "investigating the claims." Love that. Investigating. Like they found a hoof print in the mud and formed a committee.
For those not keeping score at home, Clop has been on an absolute tear lately, exploiting a hole in the fence in MOVEit file transfer software to vacuum up sensitive data from organizations that absolutely should have known better. GE and Philips are just the latest names on what is becoming a very long, very embarrassing list.
The stolen goods reportedly include military and aviation-adjacent data from GE. Which is fine. Totally fine. Nothing to worry about there. I'm sure the Wolves will use it responsibly.
And Philips, bless their hearts, makes medical equipment. So that's a fun wrinkle. Patient data, device data, who knows what else. All potentially out there now because someone couldn't be bothered to apply ointment to a known vulnerability before Clop showed up with a bucket.
That's the part that really makes me want to lie face-down in the pasture and never get up. This wasn't some mysterious hole in the fence. MOVEit's vulnerability was known. The shearing schedule existed. The Shepherds just looked at it, nodded thoughtfully, and went back to their quarterly earnings presentation.
I'm not even angry anymore. I'm just tired.
The Lambs didn't click anything this time, which is honestly a refreshing change of pace. This one lands squarely on the operations teams and the Shepherds who decide that patching is a "Q3 priority." Enjoy your Q3, I guess.
Remediation
Look. Here's what you do. Right now. Tonight.
- Patch MOVEit. If you haven't, I genuinely don't know what to tell you. Dip the flock. Apply the ointment. Do it.
- Audit your file transfer tools. All of them. Every dark corner of the pasture where data is quietly moving around unsupervised.
- Segment sensitive data. Military contracts and patient records should not be sitting in the same field as everything else.
- Check your logs for Clop indicators. CISA has published them. They're free. You have no excuse.
- Actually enforce your patching SLAs. Write it down. Put it on a fence post. Tattoo it somewhere visible.
Clop didn't beat you with sophistication. They beat you with patience and a calendar.
Go get some sleep. I won't.
Original Report: https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/