Shell USA, Inc. reported a cybersecurity event involving the MOVEit Transfer vulnerability affecting employees of its acquired company, BG Group. The CL0P hacker group exploited the vulnerability to exfiltrate personal data, including PII and government IDs, from one New Hampshire resident. Shell discovered the incident on May 31, 2023, patched the vulnerability on June 1, and notified the NH Attorney General and affected individuals in July 2023.
Affected (this filing): 1