ZeroHour

clop

ransomware group · aka Clop, Cl0p, TA505, FIN11 (related tracking, Mandiant), Lace Tempest (Microsoft) · Russia (widely assessed as Russian-speaking; exact attribution unknown) · active since 2019 (Clop ransomware); precursor TA505/FIN11 activity tracked since 2016

Victims · 7d
0▼2
Victims · 30d
2active targets
Victims · 90d
90
All-time (tracked)
2.3Ksince 2021-09-09
Last post
09-10 01:43UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Clop (Cl0p) is a Russian-speaking data-extortion group long associated with the TA505 and FIN11 actor designations, known for high-volume extortion built on data theft rather than file encryption. The group is best known for mass exploitation of managed file transfer products: Accellion FTA (2020-21), SolarWinds Serv-U (2021), Fortra GoAnywhere (2023), Progress MOVEit (2023), Cleo (2024), and Oracle E-Business Suite (2025), affecting thousands of organizations. Its playbook combines SQL injection and webshell exploitation for initial access, large-scale exfiltration, leak-site listings, and mass email extortion campaigns aimed at victims' customers and partners. Public impact tallies (Emsisoft, 2023) counted 2,700+ organizations affected in the MOVEit campaign, but a confirmed aggregate earnings figure has not been published. Leak-site tracking on this dashboard shows continued activity, with 2 posts in the past 7 days (HENRYPRATT.COM, HARLEY-DAVIDSON.COM) as of 2026-09-10.

Tactics & tooling
  • Mass exploitation of internet-facing managed file transfer software (MOVEit, GoAnywhere, Accellion FTA, Serv-U, Cleo, Oracle EBS)
  • Exfiltration-first extortion: data theft without encryption; victims published on the Cl0p leak site
  • SQL injection and webshell deployment in file-transfer intrusions (e.g., MOVEit human2.aspx webshell)
  • Mass email extortion campaigns sent to victims' customers and partners to amplify pressure
  • Historic spearphishing with macro-enabled Office documents for initial access (TA505-era)
  • Use of rclone for bulk exfiltration reported in some file-transfer campaigns
  • Ransomware deployment (Clop) in some intrusions, though major campaigns since 2023 are largely encryption-free
  • Public deadlines on leak-site listings to pressure negotiations
Targeted sectors
Financial servicesInsuranceHealthcareGovernmentEducationEnergyManufacturingLegal
Notable public victims

Shell (Accellion FTA, 2020-21; MOVEit, 2023), Deloitte (MOVEit, 2023), Sony Interactive Entertainment (MOVEit, 2023), US Department of Energy (MOVEit, 2023), British Airways and BBC (via payroll provider Zellis, GoAnywhere campaign, 2023), Community Health Systems (GoAnywhere, 2023), New Zealand Stock Exchange (Accellion FTA, 2020), Singing River Health System (Accellion FTA, 2020-21), Harley-Davidson (listed on Cl0p leak site)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
CPS.EDU · Jan 24, 2025
WESTERNALLIANCEBANK.COM · Jan 24, 2025
CLEO.COM · Jan 24, 2025
CLAWLOGISTICS.COM · Jan 24, 2025
LINFOX.COM · Jan 24, 2025
ESPRIGAS.COM · Jan 24, 2025
PISPL.IN · Jan 24, 2025
BLUEYONDER.COM · Jan 24, 2025
CENTRIC.EU · Jan 23, 2025
JOMARSOFTCORP.COM · Jan 21, 2025
MERCURYGATE.COM · Jan 18, 2025
DURAYDUNCAN.COM · Jan 13, 2025
EKOMERCIO.COM · Jan 13, 2025
VELSOL.COM · Jan 7, 2025
WSINC.COM · Jan 7, 2025
EMPRESARIA.COM · Dec 18, 2024
IMSPLGROUP.COM · Dec 18, 2024
SPECTRUMCHEMICAL.COM · Nov 6, 2024
HUBBARDHALL.COM · Nov 6, 2024
FULTON.COM · Oct 10, 2024
HARTSON-KENNEDY.COM · Oct 10, 2024
LIFTING.COM · Oct 10, 2024
ARCHIVE10 · Sep 28, 2024
ORCHID-ORTHO.COM · Sep 14, 2024
SOLOMONUS.COM · Jul 24, 2024
CIFSOLUTIONS.COM · Jun 20, 2024
NJORALSURGERY.COM · Jun 12, 2024
UNICRED.COM.AR · May 30, 2024
EMPIRECOMFORT.COM · May 30, 2024
PRIMARYSYS.COM · May 30, 2024
COMPEXLEGAL.COM · May 5, 2024
PINNACLEENGR.COM · May 5, 2024
MCKINLEYPACKAGING.COM · May 5, 2024
PILOTPEN.COM · May 5, 2024
HUDSONBUSSALES.COM · Mar 25, 2024
SJCME.EDU · Mar 25, 2024
THAISUMMIT.US · Mar 4, 2024
THESAFIRCHOICE.COM · Mar 4, 2024
PEDDIE.ORG · Feb 27, 2024
BRADSHAW-MEDICAL.COM · Feb 24, 2024
BRONSTEIN-CARMONA.COM · Feb 13, 2024
SANDALAWOFFICES.COM · Feb 2, 2024
DELPHINUS.COM · Jan 3, 2024
DSG-US.COM · Dec 17, 2023
NCCU.EDU · Nov 28, 2023
SWEETLAKE.COM · Nov 23, 2023
ARCHIVE9 · Nov 23, 2023
ARCHIVE8 · Nov 23, 2023
ARCHIVE7 · Nov 23, 2023
ARCHIVE6 · Nov 23, 2023

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .