ZeroHour

clop

ransomware group · aka Clop, Cl0p, TA505, FIN11 (related tracking, Mandiant), Lace Tempest (Microsoft) · Russia (widely assessed as Russian-speaking; exact attribution unknown) · active since 2019 (Clop ransomware); precursor TA505/FIN11 activity tracked since 2016

Victims · 7d
0▼2
Victims · 30d
2active targets
Victims · 90d
90
All-time (tracked)
2.3Ksince 2021-09-09
Last post
09-10 01:43UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Clop (Cl0p) is a Russian-speaking data-extortion group long associated with the TA505 and FIN11 actor designations, known for high-volume extortion built on data theft rather than file encryption. The group is best known for mass exploitation of managed file transfer products: Accellion FTA (2020-21), SolarWinds Serv-U (2021), Fortra GoAnywhere (2023), Progress MOVEit (2023), Cleo (2024), and Oracle E-Business Suite (2025), affecting thousands of organizations. Its playbook combines SQL injection and webshell exploitation for initial access, large-scale exfiltration, leak-site listings, and mass email extortion campaigns aimed at victims' customers and partners. Public impact tallies (Emsisoft, 2023) counted 2,700+ organizations affected in the MOVEit campaign, but a confirmed aggregate earnings figure has not been published. Leak-site tracking on this dashboard shows continued activity, with 2 posts in the past 7 days (HENRYPRATT.COM, HARLEY-DAVIDSON.COM) as of 2026-09-10.

Tactics & tooling
  • Mass exploitation of internet-facing managed file transfer software (MOVEit, GoAnywhere, Accellion FTA, Serv-U, Cleo, Oracle EBS)
  • Exfiltration-first extortion: data theft without encryption; victims published on the Cl0p leak site
  • SQL injection and webshell deployment in file-transfer intrusions (e.g., MOVEit human2.aspx webshell)
  • Mass email extortion campaigns sent to victims' customers and partners to amplify pressure
  • Historic spearphishing with macro-enabled Office documents for initial access (TA505-era)
  • Use of rclone for bulk exfiltration reported in some file-transfer campaigns
  • Ransomware deployment (Clop) in some intrusions, though major campaigns since 2023 are largely encryption-free
  • Public deadlines on leak-site listings to pressure negotiations
Targeted sectors
Financial servicesInsuranceHealthcareGovernmentEducationEnergyManufacturingLegal
Notable public victims

Shell (Accellion FTA, 2020-21; MOVEit, 2023), Deloitte (MOVEit, 2023), Sony Interactive Entertainment (MOVEit, 2023), US Department of Energy (MOVEit, 2023), British Airways and BBC (via payroll provider Zellis, GoAnywhere campaign, 2023), Community Health Systems (GoAnywhere, 2023), New Zealand Stock Exchange (Accellion FTA, 2020), Singing River Health System (Accellion FTA, 2020-21), Harley-Davidson (listed on Cl0p leak site)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
MCH-GROUP.COM FILES PART33 - D\FTP-Drive\ PUBLISHED · May 20, 2022
PERBIT.COM FILES PART1 - 10.182.179.241\C$\sbs_prbt_backup_cifs1_vol1\SQL Backup\ PUBLISHE · May 13, 2022
KSSENTERPRISES.COM FILES PART4 - 10.250.1.6\D$\ PUBLISHED · May 13, 2022
ZISSERFAMILYLAW.COM FILES PART8 - D\Shares\DATA\ PUBLISHED · May 13, 2022
SA1SOLUTIONS.COM FILES PART8 - 192.168.10.238\D$\Storage - Picseli\PICSELI 2014 ONWARDS\C · May 13, 2022
ORBITELECTRIC.COM FILES PART6 - 192.168.10.23\ORBIT_ART\ChristinaW\ PUBLISHED · May 13, 2022
OAKDELL.COM FILES PART8 - 192.168.100.253 PUBLISHED · May 13, 2022
JDAVIDTAXLAW.COM FILES PART8 - E\ PUBLISHED · May 13, 2022
FAIR-RITE.COM FILES PART8 - 172.16.20.110, 172.16.20.111, 172.16.20.126, 172.16.20.151, 17 · May 13, 2022
DRIVEANDSHINE.COM FILES PART8 - 192.168.200.73\C$ PUBLISHED · May 13, 2022
DRC-LAW.COM FILES PART8 - 10.10.1.2\C$\Shares\Data\Documents\Clients\Q-Z\ PUBLISHED · May 13, 2022
ALTERNATIVETECHS.COM FILES PART8 - C\Shares\Alternative\accounting\ARCHIVE - former staff · May 13, 2022
JBINSTANTLAWN.NET FILES PART11 - JB-SERVER\Users\Anne-Marie Tribbett PUBLISHED · May 13, 2022
ALEXIM.COM FILES PART11 - 192.168.3.5\shares PUBLISHED · May 13, 2022
AFJCONSULTING.NET FILES PART6 - E\data\documents\Client Folders\ PUBLISHED · May 13, 2022
MCH-GROUP.COM FILES PART32 - D\FTP-Drive\ PUBLISHED · May 13, 2022
KSSENTERPRISES.COM FILES PART3 - 10.250.1.6\D$\ PUBLISHED · May 7, 2022
ZISSERFAMILYLAW.COM FILES PART7 - D\Shares\DATA\ PUBLISHED · May 7, 2022
SA1SOLUTIONS.COM FILES PART7 - 192.168.10.238\D$\Storage - Customers PUBLISHED · May 7, 2022
ORBITELECTRIC.COM FILES PART5 - 192.168.10.23\ORBIT_ART\ PUBLISHED · May 7, 2022
OAKDELL.COM FILES PART7 - 192.168.100.137\C$\Users\clillywhite\ PUBLISHED · May 7, 2022
JDAVIDTAXLAW.COM FILES PART7 - E_Previous_Employees\ PUBLISHED · May 7, 2022
FAIR-RITE.COM FILES PART7 - 172.16.20.11, 172.16.20.100 PUBLISHED · May 7, 2022
DRIVEANDSHINE.COM FILES PART7 - 192.168.200.151 PUBLISHED · May 7, 2022
DRC-LAW.COM FILES PART7 - 10.10.1.2\C$\Shares\Data\Documents\Clients\A-H\Alpine Consulting · May 7, 2022
ALTERNATIVETECHS.COM FILES PART7 - C\Shares\Alternative\accounting\ARCHIVE - former staff · May 7, 2022
JBINSTANTLAWN.NET FILES PART10 - JB-SERVER\D$\ServerFolders\Company\ PUBLISHED · May 7, 2022
ALEXIM.COM FILES PART10 - 192.168.3.5\Mail\csanchez\ PUBLISHED · May 7, 2022
AFJCONSULTING.NET FILES PART5 - E\data\documents\Client Folders\ PUBLISHED · May 7, 2022
MCH-GROUP.COM FILES PART31 - 172.16.1.100, 172.16.103.43 PUBLISHED · May 7, 2022
BOLTONUSA.COM FILES PART35 - 10.0.0.20\c$\BOD_HQ_CIFS\DB_Dept\DB_DEPT\CLIENT\WV MPOB PUBLI · May 7, 2022
KSSENTERPRISES.COM FILES PART2 - 10.250.1.6\D$\ PUBLISHED · Apr 29, 2022
ZISSERFAMILYLAW.COM FILES PART6 - D\Shares\DATA\ PUBLISHED · Apr 29, 2022
SA1SOLUTIONS.COM FILES PART6 - 192.168.10.238\D$\Sharepoint\SA1 SOLUTIONS\Helpdesk - Docu · Apr 29, 2022
SSMSJUSTICE.COM FILES PART33 - 192.168.1.247, F PUBLISHED · Apr 29, 2022
ORBITELECTRIC.COM FILES PART4 - 192.168.10.3\E$\USERS\ PUBLISHED · Apr 29, 2022
OAKDELL.COM FILES PART6 - 192.168.100.137\C$\Users\clillywhite\ PUBLISHED · Apr 29, 2022
JDAVIDTAXLAW.COM FILES PART6 - E_Previous_Employees\ PUBLISHED · Apr 29, 2022
FAIR-RITE.COM FILES PART6 - 172.16.20.10 PUBLISHED · Apr 29, 2022
DRIVEANDSHINE.COM FILES PART6 - 192.168.200.14, 192.168.200.17 PUBLISHED · Apr 29, 2022
DRC-LAW.COM FILES PART6 - 10.10.1.2\C$\Shares\Data\Documents\Clients\A-H\Alpine Consulting · Apr 29, 2022
ALTERNATIVETECHS.COM FILES PART6 - C\Shares\Alternative\accounting\ARCHIVE - former staff · Apr 29, 2022
JBINSTANTLAWN.NET FILES PART9 - JB-SERVER\D$\ServerFolders\Company\Accounting\Digital File · Apr 29, 2022
ALEXIM.COM FILES PART9 - 192.168.3.5\Mail\csanchez\ PUBLISHED · Apr 29, 2022
AFJCONSULTING.NET FILES PART4 - E\data\documents\Client Folders\ PUBLISHED · Apr 29, 2022
MCH-GROUP.COM FILES PART30 - 172.16.60.11\ PUBLISHED · Apr 29, 2022
EDAN.COM FILES PART29 - 192.168.2.200\D$\法务部\法务部\06-离职交接文件\宁姐\ PUBLISHED · Apr 29, 2022
BOLTONUSA.COM FILES PART34 - 10.0.0.20\c$\BOD_HQ_CIFS\DB_Dept\DB_DEPT\CLIENT\PBGC-DISC_Mul · Apr 29, 2022
KSSENTERPRISES.COM FILES PART1 - 10.250.1.6\D$\ PUBLISHED · Apr 23, 2022
ZISSERFAMILYLAW.COM FILES PART5 - D\Shares\BEACHESDATA\Business Office\Degnan, Jim\STI 201 · Apr 23, 2022

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .