← Siemens Gamesa Renewable Energy

2023 Siemens Energy AG (Siemens Gamesa parent) — MOVEit Transfer / Cl0p data theft confirmation

2023 Unknown records affected Share on X

Data compromised

Corporate files exfiltrated from file-transfer infrastructure—Siemens Energy downplayed critical operational or safety systems impact in contemporaneous statements

Technical writeup

Siemens Energy—majority owner of Siemens Gamesa Renewable Energy—acknowledged theft of data from internet-facing MOVEit Transfer instances during the mid-2023 Cl0p mass-exploitation wave, telling reporters it saw no compromise of critical infrastructure controls while reinforcing patch cadence. BreachHistory associates the record with the Siemens Gamesa slug because securities and press narratives tied SGRE branding to the parent's consolidated cyber portfolio.

Root cause

CVE-2023-34362 MOVEit Transfer zero-day leveraged by Cl0p affiliates

References