Sustainability Business division of Schneider Electric
bd_3828d61d9d98c7d6 · schema v1 · pii pii-v1
Full breach record for Sustainability Business division of Schneider Electric →Schneider Electric's Sustainability Business division suffered a ransomware attack by actor 'Cactus' exploiting CVE-2023-48365 on a Qlik Sense server. Access occurred Dec 27, 2023–Jan 17, 2024. One NH resident's name and passport number were exposed. Incident contained Jan 31, 2024; data posted to dark web Feb 19, 2024. Notification sent Oct 31, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 27, 2023
Begins
Jan 17, 2024
Discovered
Oct 31, 2025
Filed
vs. sector median
+75 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_210ff50e027143092025-10-31Verified
- Vermont State AGbd_832b13d8ed674d1a2025-10-31Candidate
- Massachusetts State AGbd_8ea32e208201ea1c2025-10-31Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.