Categories: Technology

Swiss health insurer and holiday provider confirm data theft by Russian gangs

The insurance company ÖKK and the holiday park operator Landal, which also operates in Switzerland, confirm a hacker attack by the “Clop” gang to Watson. Other victims are likely to follow.
Daniel Schurter

The ransomware gang Clop fulfilled their threat: on the leak site of the notorious cybercriminals, numerous names of some well-known companies were praised on Thursday. Among them: the world’s largest mineral oil and natural gas company Shell, but also the Swiss health insurer ÖKK and the holiday park operator Landal, which is also active in this country.

The outflow of data has so far remained limited, according to research by Watson. More casualties are likely to follow.

The history:

Last week, the Russian-speaking gang announced on their dark web leak site that they had massively hacked businesses thanks to a little-known vulnerability in a file transfer tool. The cybercriminals did not name names at the time, but asked those affected who used the associated software tool to contact them by June 14, 2023 at the latest.

Important to know: These are not ransomware attacks where the attackers try to encrypt their victims’ IT systems with malware.

The perpetrators exploited vulnerabilities in the MOVEit Transfer software to secretly steal data from the servers. And now, as part of the “Hack and Leak” attack, they are threatening to publish the data on the dark web.

That says the affected health insurer

watson has on Swiss health insurance company ÖKK early. The Graubünden company confirms a corresponding cyber attack in connection with the file transfer software MOVEit Transfer.

“We are among the presumably many affected. Our core health data system is not affected,” explains Patrick Eisenhut, Head of Communications, ÖKK. Personal data such as first and last name are affected.

“We currently see no reason to comply with the demands.”

“We have taken immediate measures and are working with external partners,” says the ÖKK spokesperson. The cybersecurity specialists have “given all-clear so far” and the affected platform (MOVEit Transfer) has been rebooted.

The partner organizations have already been informed and are currently investigating whether they can inform customers directly.

According to the description on its website, ÖKK is an insurance company with 30 branches operating throughout Switzerland. Customers: Approximately 190,000 individuals and 13,000 companies and public institutions. The annual premium volume is 800 million Swiss francs. ÖKK employs about 490 people and about 15 apprentices.

What does Landal say?

Simone Clemens, media spokeswoman for Landal GreenParks, upon request from watson, confirms that the company uses MOVEit software, which is used worldwide. As reported in the news, cyber criminals have managed to hack into this software.

“The cybercriminals also gained access to Landal GreenParks and guest data. We don’t know if they actually used this access.”

As a precaution, the Dutch Data Protection Authority and the guests have been informed. In addition, the server in question was immediately shut down and reconfigured “to ensure that unauthorized persons no longer have access”.

The media spokeswoman explains:

“The personally identifiable information that may have been stolen does not include passwords, financial information, or information about future bookings. These are the names and contact details of about 12,000 guests. Given the magnitude of this MOVEit hack, we believe more companies have reported or will report this hack.”

How many victims are there in total?

This is unknown. Hundreds of companies and organizations around the world have reportedly used MOVEit Transfer file transfer software.

Clop’s dark web page lists a few new names so far, including:

  • 1st source: American bank.
  • Data Site: Cloud provider from Germany
  • First National Bankers’ Bank: USA
  • Heidelberger Druckmaschinen AG: Germany
  • Landal Green Parks: Holiday park provider headquartered in Germany, also active in Switzerland
  • Leggett & Platt: major American furniture manufacturer
  • National Student Clearing House: American non-profit educational organization.
  • Putnam Investments: The American company manages about $ 165 billion in customer assets.
  • Shell: The multinational oil company headquartered in London is active in more than 140 countries and has an annual turnover of around USD 180 billion.
  • United Healthcare Student Resources: American health insurance company.
  • University of Georgia: American educational institution

As the example of ÖKK shows, the question is whether these organizations have suffered major data breaches.

Could there also have been massive data breaches?

“Absolutely,” says Swiss IT security expert Marc Ruef.

“Here, for example, the network topology plays an important role: how is the network structured, which transitions are protected by firewalls and where is the attacked component located. Anyone who did their homework didn’t make it easy for the attackers.”

Estimating the scope and effects of the Clop massive attack is very difficult. An “exploitation” (taking advantage of the vulnerability) started very early and misled many companies.

“The question arises to what extent the attackers have been able to automate the exploitation of the vulnerability and the collection of the data. We assume that the attackers had to do a lot of manual access, especially in the early stages, which made attack enforcement quite slow.”
Comment on the topic?
Watson editor Daniel Schurter can also be reached anonymously through the encrypted messenger app Threema. His “Threema ID” is: ACYMFHZX. Or you write to daniel.schurter [at] protonmail.com. If you register (free) with the Swiss secure mail provider, you can send encrypted e-mails.

Daniel Schurter

Source: Watson

Share
Published by
Ella

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago