Menu
Browse

Cyber Incident Victim: Munich Re

Date:

Mar 2023

Location:

Germany

Summary

A ransomware group exploited a critical vulnerability in Fortra's GoAnywhere secure file transfer tool, compromising data from multiple organizations including a municipal government, a consumer rewards program, and a statutory pension fund. The attackers accessed files via a third-party vendor, prompting an investigation into potential exposure of resident and employee information. The impacted municipality confirmed unauthorized data access but had not yet determined the full scope of affected individuals, while the pension agency notified current and former staff about compromised employment records. The rewards program stated no customer data was exposed. Over 130 organizations worldwide were reportedly breached through this campaign.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The Clop ransomware gang exploited a remote code execution vulnerability (CVE-2023-0669) in Fortra's GoAnywhere MFT secure file transfer tool, initiating a widespread hacking campaign that impacted numerous organizations by March 2023. Fortra had previously notified customers that attackers abused this zero-day flaw in systems with exposed administrative consoles. Clop claimed responsibility for breaching over 130 organizations within ten days starting in February 2023, with victim organizations continuing to emerge through March. Among those affected were the City of Toronto, UK-based Virgin Red, and the Pension Protection Fund (PPF). The City of Toronto confirmed on March 20, 2023, that it had detected unauthorized access to its data through a third-party vendor's compromised GoAnywhere instance. Initial investigations indicated the breach was limited to files that could not be processed through the vendor's secure transfer system, though the city had not yet confirmed whether resident data was compromised.

Cyber Incident Image

The breach allowed Clop to access Virgin Red's files via the same GoAnywhere vulnerability, though Virgin confirmed no customer or employee personal data was exposed. The PPF disclosed that current and former employee data was compromised, prompting direct notifications to affected individuals and offers of monitoring services. PPF ceased using GoAnywhere following the incident and collaborated with Fortra, security partners, and law enforcement during its investigation. Other organizations including Hitachi Energy, Saks Fifth Avenue, and cybersecurity firm Rubrik also confirmed breaches stemming from the same zero-day exploit. Toronto emphasized its commitment to data protection and ongoing efforts to assess the scope of compromised information, pledging to notify residents if personal data was affected. The incident underscored operational disruptions and data exposure risks linked to third-party vendor vulnerabilities.

Sources
Sources available to members
1 source