Select Page

Incident: Fortescue Metals admits it suffered breach, Cl0p claims credit | iTWire

Incident: Fortescue Metals admits it suffered breach, Cl0p claims credit | iTWire

Australian Mining Cyber Incident, 18 July 2023

Iron ore giant Fortescue Metals targeted by Russian ransomware group

Australian mining company confirms hack occurred on 28 May but data disclosed ‘was not confidential in nature’

Source: Incident: Fortescue Metals admits it suffered breach, Cl0p claims credit | iTWire

View more incidents from Mining and Resources sector and incidents relating to Third-Party Risk

Australian firm Fortescue Metals Group, one of the world’s largest and lowest cost producers of iron ore which is transitioning into a global green energy and metals company, has been hit by a data breach with the ransomware group Cl0p claiming it was behind the intrusion.

Cl0p on its site on the dark web, the ransomware group listed the fact that it had effected a breach of the firm, commenting “The company doesn’t care about its customers, it ignored their security!!!” – SK: I guess they refused to pay the ransom.

A Fortescue spokesperson: “We take the protection of our employees’ personal information seriously and we have strong measures in place to safeguard our business from potential cyber threats.

“Despite these efforts, Fortescue was subject to a low-impact cyber incident on 28 May which resulted in the disclosure of a small portion of data from our networks.

“Importantly, our investigations showed that this information was not confidential in nature.

“We notified the Australian Cyber Security Centre of the incident, and our internal investigation and remediation actions are now complete.”

Cl0P did not provide any further details about the quantum of data stolen, if any.

It is unclear whether Cl0p attacked Fortescue through the secure managed file transfer software MOVEit Transfer or through some other vector.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

What changes will be made under federal government’s privacy law reform? | ABC NEWS

The federal government has unveiled plans to strengthen privacy laws. The proposed reforms take aim at identity fraud and give people the right to erase their data from online platforms. [...]

Australians to gain greater control over compromised identity documents with new IDLock scheme

The Albanese Government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]

Two WA Men Face Court Over Global Cybercrime Syndicate Allegations | 10 News

Two WA men have faced court, accused of masterminding of a sophisticated cyber-crime syndicate. The pair arrested following raids across three suburbs in a joint investigation between Australian police and [...]

New privacy laws target smart glasses and AI tech | 7NEWS

The Federal Government is developing new privacy laws targeting AI technology, including smart glasses and social media platforms. The proposed measures include expanding the Credential Protection Register through a new [...]

ASX creates deputy CISO role

Key points The ASX has created a new deputy chief information security officer role, with Hanlie Botha appointed as its first holder. • Botha joins ASX … [...]

Bendigo and Adelaide Bank Limited (Bendigo Bank) has conceded it has breached its obligations under the Banking Executive Accountability Regime … [...]

Mopping up AI Slop: Fair Work Commission taking ac... | Clayton Utz

What you need to know On 24 August 2026, Justice Hatcher, President of the Fair Work Commission (FWC), released a Guidance Note on the use of … [...]

Busted! Alleged Aussie hackers linked to TeamPCP arrested in joint AFP-FBI-WAPF operation

Two men in their early 20s are to face a total of 14 charges for their alleged part in a global cybercrime organisation. • Fri, 28 Aug 2026 • … [...]

Financial Crimes Squad detectives have charged a telecommunications employee with allegedly accessing customer information without authorisation and … [...]

Sydney-based telco employee accused of selling customer data

Key points A 30-year-old telco employee has been charged over allegedly accessing customer data and selling it to "criminal groups". • NSW Police made … [...]

The Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) are urging financial market … [...]

Aussie publisher Hachette restoring systems following ‘detection of unauthorised activity’ on network

Bookstores are facing stocking delays in the wake of a cyber attack, as the publisher says a timeline for return to full operations is impossible to … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading