HackingVulnerability ExploitCapture Stored DataCL0PData ExfiltratedTargetedCustomer Data InvolvedPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
SHELL USA, INC.
bd_b4a55b1a587ce55d · schema v1 · pii pii-v1
Full breach record for SHELL USA, INC. →Shell USA, Inc. reported a cybersecurity event involving the MOVEit Transfer vulnerability affecting employees of its acquired company, BG Group. The CL0P hacker group exploited the vulnerability to exfiltrate personal data, including PII and government IDs, from one New Hampshire resident. Shell discovered the incident on May 31, 2023, patched the vulnerability on June 1, and notified the NH Attorney General and affected individuals in July 2023.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/shell-usa-20230727.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- 1d2545f1193c004a10988dc2c76edcdc4168cb56e30cf9f7fcef5b25f37c04df
Reporting entity
- Name
- SHELL USA, INC.norm: shell usa
Victim entity
- Name
- SHELL USA, INC.norm: shell usa
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jul 27, 2023
- Affected individuals
- 1
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access· CL0P
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- CL0PExternalFinancial
- Regulator citations
- Submitted notice to Consumer Protection Bureau, Office of the Attorney General, Concord, NH
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(57 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.