ZeroHour

clop

ransomware group · aka Clop, Cl0p, TA505, FIN11 (related tracking, Mandiant), Lace Tempest (Microsoft) · Russia (widely assessed as Russian-speaking; exact attribution unknown) · active since 2019 (Clop ransomware); precursor TA505/FIN11 activity tracked since 2016

Victims · 7d
2▲2 vs prev. week
Victims · 30d
2active targets
Victims · 90d
90
All-time (tracked)
2.3Ksince 2021-09-09
Last post
09-10 01:43UTC
Estimated earnings
public reporting
Profile · glm-5.3-flash · updated

Clop (Cl0p) is a Russian-speaking data-extortion group long associated with the TA505 and FIN11 actor designations, known for high-volume extortion built on data theft rather than file encryption. The group is best known for mass exploitation of managed file transfer products: Accellion FTA (2020-21), SolarWinds Serv-U (2021), Fortra GoAnywhere (2023), Progress MOVEit (2023), Cleo (2024), and Oracle E-Business Suite (2025), affecting thousands of organizations. Its playbook combines SQL injection and webshell exploitation for initial access, large-scale exfiltration, leak-site listings, and mass email extortion campaigns aimed at victims' customers and partners. Public impact tallies (Emsisoft, 2023) counted 2,700+ organizations affected in the MOVEit campaign, but a confirmed aggregate earnings figure has not been published. Leak-site tracking on this dashboard shows continued activity, with 2 posts in the past 7 days (HENRYPRATT.COM, HARLEY-DAVIDSON.COM) as of 2026-09-10.

Tactics & tooling
  • Mass exploitation of internet-facing managed file transfer software (MOVEit, GoAnywhere, Accellion FTA, Serv-U, Cleo, Oracle EBS)
  • Exfiltration-first extortion: data theft without encryption; victims published on the Cl0p leak site
  • SQL injection and webshell deployment in file-transfer intrusions (e.g., MOVEit human2.aspx webshell)
  • Mass email extortion campaigns sent to victims' customers and partners to amplify pressure
  • Historic spearphishing with macro-enabled Office documents for initial access (TA505-era)
  • Use of rclone for bulk exfiltration reported in some file-transfer campaigns
  • Ransomware deployment (Clop) in some intrusions, though major campaigns since 2023 are largely encryption-free
  • Public deadlines on leak-site listings to pressure negotiations
Targeted sectors
Financial servicesInsuranceHealthcareGovernmentEducationEnergyManufacturingLegal
Notable public victims

Shell (Accellion FTA, 2020-21; MOVEit, 2023), Deloitte (MOVEit, 2023), Sony Interactive Entertainment (MOVEit, 2023), US Department of Energy (MOVEit, 2023), British Airways and BBC (via payroll provider Zellis, GoAnywhere campaign, 2023), Community Health Systems (GoAnywhere, 2023), New Zealand Stock Exchange (Accellion FTA, 2020), Singing River Health System (Accellion FTA, 2020-21), Harley-Davidson (listed on Cl0p leak site)

Estimated earnings

No public figure.

Leak-site victims

VictimDiscoveredDetails
HELIXESG.COM · Nov 13, 2025
TPICOMPOSITES.COM · Nov 13, 2025
FLUKE.COM · Nov 13, 2025
SATO-GLOBAL.COM · Nov 13, 2025
FORBESMARSHALL.COM · Nov 13, 2025
PENS.COM · Nov 13, 2025
ENTRUST.COM · Nov 13, 2025
DARTMOUTH.EDU · Nov 11, 2025
PAFL.COM.PK · Nov 11, 2025
SAMCRETE.COM · Nov 11, 2025
GAEAGLOBAL.COM · Nov 11, 2025
P2ENERGYSERVICES.COM · Nov 11, 2025
GLOBUSANDCOSMOS.COM · Nov 11, 2025
ENNVEE.COM · Nov 11, 2025
CARGLASS.DE · Nov 11, 2025
VITAMIX.COM · Nov 11, 2025
GARDENOFLIFE.COM · Nov 11, 2025
NHS.UK · Nov 11, 2025
ZANACO.CO.ZM · Nov 6, 2025
WASHINGTONPOST.COM · Nov 6, 2025
INFORMA.COM (EBS) · Nov 6, 2025
RHEEM.COM · Nov 6, 2025
WOODPLC.COM · Nov 6, 2025
ELSEWEDYELECTRIC.COM · Nov 6, 2025
KIER.CO.UK · Nov 6, 2025
LOGITECH.COM · Nov 6, 2025
INTERNATIONAL.COM · Nov 6, 2025
KIRBYCORP.COM · Nov 6, 2025
TRIMBLE.COM · Nov 6, 2025
MKS.COM · Nov 6, 2025
LV.COM · Nov 3, 2025
ANSELL.COM · Oct 30, 2025
MASTEC.COM · Oct 28, 2025
DAVIDYURMAN.COM · Oct 25, 2025
PANAMERICANSILVER.COM · Oct 25, 2025
COXENTERPRISES.COM · Oct 25, 2025
HRSD.COM · Oct 25, 2025
SE.COM (EBS) · Oct 23, 2025
CSCGLOBAL.COM · Oct 23, 2025
AUSENCO.COM · Oct 23, 2025
LKQCORP.COM · Oct 23, 2025
MILGARD.COM · Oct 22, 2025
COPELAND.COM · Oct 22, 2025
EMERSON.COM - (EBS) · Oct 18, 2025
AA.COM - (EBS) · Oct 18, 2025
WITS.AC.ZA · Oct 18, 2025
HARVARD.EDU · Oct 12, 2025
PHARMARON.COM · Jul 7, 2025
PILOTTHOMAS.COM · Jun 27, 2025
CHECKCITY.COM · May 12, 2025

In the newsAll →

Victim posts come from the group's leak site via RansomLook and are claims, not confirmations. The profile is written by the model from public reporting and refreshed monthly; earnings figures cite their source and year. First tracked .