SHELL USA, INC.
bd_b4a55b1a587ce55d · schema v1 · pii pii-v1
Full breach record for SHELL USA, INC. →Shell USA, Inc. notified the NH Attorney General of a cybersecurity event involving the MOVEit Transfer software vulnerability. On May 31, 2023, Shell discovered unauthorized access to personal data of one New Hampshire resident, an employee of BG Group (a Shell affiliate). The attack was attributed to the CL0P hacker group exploiting a vulnerability in Progress Software's MOVEit Transfer. Data was exfiltrated. Shell patched the vulnerability on June 1, 2023, and contained the incident. Affected individuals were offered complimentary Experian IdentityWorks services.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Discovered
Jul 27, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_6fb7015b30a4c30a2023-07-26 · +1dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.