Cactus ransomware hackers say they stole terabytes of Schneider Electric data

ID theft
Image credit: Pixabay (Image credit: Future)

The Cactus ransomware hackers have claimed responsibility for the recent cyberattack on Schneider Electric, claiming to have stolen 1.5TB of sensitive data in the heist.

The ransomware group added the energy giant to its data leak website, posted samples of the stolen data, and are demanding money in exchange for keeping the data secure.

While it is impossible to determine exactly what type of data the group stole at this point, the hackers are thought to have accessed Schneider Electric’s Sustainability Business, which provides renewable energy and regulatory compliance consulting to large corporations around the world. Some of its clients include DHL, Hilton, Lexmark, and Walmart.

Contained attack

The group also posted a 25MB sample, which includes snapshots of people’s passports, and scans of different non-disclosure agreements. The group is now asking for money in exchange for keeping the data safe, but we don’t know exactly how much money they’re asking for, or if Schneider Electric is even interested in paying. 

However, the media argue the data could include sensitive information about client industrial control and automation systems which, if leaked, could turn into an even bigger problem for Schneider.

Cactus is a known threat actor that was first spotted in May 2023, when researchers discovered a ransomware variant that evades detection by encrypting itself. What also makes Cactus interesting is that it has multiple modes of encryption, including a quick mode. If the operators decide to run both modes one after the other, the files will be encrypted twice and will get two file extensions. 

"From a recovery standpoint, Sustainability Business is performing remediation steps to ensure that business platforms will be restored to a secure environment,” the company said in mid-January, when the breach was first detected.  “Teams are currently testing the operational capabilities of impacted systems with the expectation that access will resume in the next two business days.” 

“From a containment standpoint, as Sustainability Business is an autonomous entity operating its isolated network infrastructure, no other entity within the Schneider Electric group has been affected.”

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Telefonica
Telefónica says it was hit by systems breach, internal data leaked online
ID theft
Hackers claim Orange attack, threaten to leak 1TB of data
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand