On Monday 20th of March 2023, the Clop ransomware gang claimed to have attacked Saks Fifth Avenue on its dark web leak site. It is believed that the incident is a part of the gang’s ongoing attacks against vulnerable GoAnywhere MFT servers using the CVE-2023-0669 vulnerability.
Since the post was released, sources have contacted Saks and a spokesperson confirmed the incident was linked to the ongoing attacks against GoAnywhere MFT servers. However, the spokesperson stated that only mock customer data has been taken from a storage location used by Saks.
© 2021 CyberEnsō – Nihon Cyber Defence Co., Ltd. All Rights Reserved.