MalwareRansomwareVulnerability ExploitCactusData ExfiltratedData EncryptedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTCVE-2023-48365MediumResolved
Sustainability Business division of Schneider Electric
bd_3828d61d9d98c7d6 · schema v1 · pii pii-v1
Full breach record for Sustainability Business division of Schneider Electric →Schneider Electric's Sustainability Business division suffered a ransomware attack by actor 'Cactus' exploiting CVE-2023-48365 on a Qlik Sense server. Access occurred Dec 27, 2023–Jan 17, 2024. One NH resident's name and passport number were exposed. Incident contained Jan 31, 2024; data posted to dark web Feb 19, 2024. Notification sent Oct 31, 2025.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_210ff50e02714309Indiana State AGfiled 2025-10-31Verified
- bd_832b13d8ed674d1aVermont State AGfiled 2025-10-31Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/schneider-electric-20251031.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 31, 2025
- Raw hash
- fafae40be7b8a3e44188f4587358bc9ca4de4cb920dae15216028f440ea57430
Reporting entity
- Name
- SCHNEIDER ELECTRIC HOLDINGS, INC.norm: schneider electric
- Domain
- se.com
Victim entity
- Name
- Sustainability Business division of Schneider Electricnorm: sustainability business division of schneider electric
Incident
- Discovered
- Jan 17, 2024
- Materiality determined
- —
- Notification sent
- Oct 31, 2025
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware· Cactus
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- CactusExternalFinancial
- Regulator citations
- reported the incident to law enforcement and has been supporting their investigation
- Initial access
- exploit_public_facing
- CVE references
Compliance
- Time to disclose
- 22 months(653 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.