WK Kellogg Confirms Data Breach Tied to Cleo Software Exploit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-50623 | Unauthenticated RCE via Unrestricted File Upload in Cleo Harmony, VLTrader, LexiCom CVE-2024-50623 is an unrestricted file upload and download flaw (CWE-434) in Cleo's managed file transfer products — Harmony, VLTrader, and LexiCom — before version 5.8.0.21. It is reachable over the network with no authentication or user interaction (CVSS 9.8, AV:N/AC:L/PR:N), letting an attacker send crafted requests that upload arbitrary files to the server. The unrestricted upload leads to remote code execution, giving the attacker full control of the host for staging, data theft, or ransomware, while the download capability risks exposure of business files the server moves with trading partners. Any organization running these products is affected, and managed file transfer servers are typically internet-facing and handle sensitive B2B data. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2024-12-13 with ransomware use noted, EPSS assigns a 98.6% probability of exploitation within 30 days, and the Clop ransomware gang has claimed dozens of breaches (some disputed), including a confirmed breach at WK Kellogg. Do: Upgrade Harmony, VLTrader, and LexiCom to 5.8.0.21 or later per vendor instructions; if upgrading is not possible, apply vendor mitigations or discontinue use of the product, as CISA's KEV entry requires. Prioritize internet-exposed instances, hunt for indicators of compromise (unexpected file writes and execution on the transfer host, new accounts, suspicious outbound connections), and restrict the service to trusted partner networks. Given known ransomware use by Clop, any suspected compromise should trigger checks for lateral movement and staged exfiltration of transferred files. | 9.8 | 99% | KEV ransomware |
| moderate≈1,000–3,000 internet-exposed Cleo servers (tens of thousands of enterprise deployments) | |
| CVE-2024-55956 | Unauthenticated File Upload RCE in Cleo Harmony, VLTrader, and LexiCom CVE-2024-55956 is an unauthenticated command-execution flaw (CWE-77) in Cleo's managed file transfer products: by default the Autorun directory automatically imports and runs files, so an unauthenticated attacker can import Bash or PowerShell commands that execute on the host. It is triggered over the network with no authentication and no user interaction (CVSS 3.1 score 9.8), by sending crafted import requests to a vulnerable Cleo server. Successful exploitation yields arbitrary command execution on the server, enabling data theft, lateral movement, and ransomware deployment. Any organization running Cleo Harmony, VLTrader, or LexiCom before 5.8.0.24 is affected — typically enterprises using these servers for EDI and partner file exchange. The flaw is actively exploited in the wild: it was added to CISA KEV on 2024-12-17 with known ransomware use (widely attributed to Cl0p), EPSS is 94% (top percentile), and confirmed downstream breaches such as WK Kellogg's have been tied to it. Do: Upgrade all Cleo Harmony, VLTrader, and LexiCom instances to 5.8.0.24 or later immediately, per the CISA KEV required action to apply vendor mitigations or discontinue use. If patching is delayed, restrict or remove internet exposure of the server. Because exploitation is confirmed and ransomware-linked, inspect the Autorun directory for unexpected imported files, review application logs for executed commands, and hunt for signs of data exfiltration or staging. | 9.8 | 94% | KEV ransomware PoC |
| largetens of thousands of installations (Cleo cites 100,000+ business customers; public internet scans showed roughly 1,000–2,000 exposed instances) |
Full article398 words · extracted from infosecurity-magazine.com · click to collapse
Sensitive employee data at WK Kellogg Co. has been exposed in a cybersecurity breach after attackers exploited a vulnerability in file transfer software used by the company.
The breach, which occurred on December 7 2024, involved unauthorized access to personnel files transferred via Cleo servers.
WK Kellogg disclosed the incident on April 4 2025, in a filing to the Maine Attorney General’s Office. The Michigan-based cereal manufacturer said it discovered the breach on February 27 and has begun notifying affected individuals by mail.
At least one employee in Maine had their name and Social Security number compromised, though the full scope of the breach remains unclear.
The attackers exploited known vulnerabilities in Cleo’s Harmony, VLTrader and LexiCom file transfer software.
One flaw, tracked as CVE-2024-50623, allowed unrestricted uploads and downloads. Although Cleo issued a patch in October 2024, security researchers later found it failed to fully protect against intrusion.
In December, a second vulnerability – CVE-2024-55956 – was discovered. This flaw allows unauthenticated users to run arbitrary bash or PowerShell commands, giving attackers a path to deploy malicious code.
Cybersecurity firms believe the Clop ransomware group is responsible for the attack.
Researchers from Arctic Wolf and Mandiant linked the breach to a broader campaign that has targeted organizations using Cleo products.
Clop publicly listed WK Kellogg on its dark web leak site in February, applying pressure on the company to respond.
“Zero-day flaws, such as those that have been exploited by the Clop ransomware group, are extremely difficult to defend against,” Erich Kron, security awareness advocate at KnowBe4.
“Because these stolen files are HR-related employee files, the information within them is liable to be very sensitive and could easily lead to identity theft for those affected.”
WK Kellogg confirmed it used Cleo servers to send personnel files to HR service providers. Those transfers were the specific target of the attack.
The company has begun offering affected individuals one year of free identity theft protection from Kroll, including credit monitoring and fraud support.
“Victims of the data breach should ensure that they have locked their credit to avoid illicit accounts being opened in their names and should be on the lookout for potential signs of identity theft,” Kron concluded.
Image credit: Katherine Welles / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/wk-kellogg-confirms-data-breach/