2023 Siemens Energy AG (Siemens Gamesa parent) — MOVEit Transfer / Cl0p data theft confirmation
Data compromised
Corporate files exfiltrated from file-transfer infrastructure—Siemens Energy downplayed critical operational or safety systems impact in contemporaneous statements
Technical writeup
Siemens Energy—majority owner of Siemens Gamesa Renewable Energy—acknowledged theft of data from internet-facing MOVEit Transfer instances during the mid-2023 Cl0p mass-exploitation wave, telling reporters it saw no compromise of critical infrastructure controls while reinforcing patch cadence. BreachHistory associates the record with the Siemens Gamesa slug because securities and press narratives tied SGRE branding to the parent's consolidated cyber portfolio.
Root cause
CVE-2023-34362 MOVEit Transfer zero-day leveraged by Cl0p affiliates