Actor · Extortion · since 2019
Clop: mass extortion without encryption
Profile of Clop, the group that exploits zero-days in file transfer tools and exposed business software to steal data at scale, then extorts without encrypting.
- Model
- Extortion without encryption · since 2019-02
- Aliases
- Cl0p, TA505, FIN11
- Ways in
- Zero-days in file transfer tools · SQL injection on exposed applications · Internet-facing ERP · Incomplete vendor patches
- Targets
- Managed file transfer (MOVEit, GoAnywhere, Cleo) · Oracle E-Business Suite · Large enterprises and public bodies · Customers of compromised suppliers
- Official advisories
- AA23-158A
By Sentrix · Published 2026-09-20
Who they are
Clop (also written Cl0p) appeared in February 2019 as an evolution of CryptoMix, according to the joint CISA and FBI advisory AA23-158A, which ties the group to the TA505 actor. The same advisory describes a ransomware-as-a-service operation that, campaign after campaign, moved away from encryption to focus on data theft and the threat of publication on its leak site. Google Threat Intelligence Group (GTIG) and Mandiant link the Clop extortion brand to the FIN11 group.
What sets Clop apart is not a piece of malware, it is a model: find an unknown vulnerability in a widely deployed, internet-facing product, exploit it across a large number of organizations within days, then negotiate with each one. Encryption becomes optional; the pressure comes from the stolen data.
How they get in
Clop targets managed file transfer software and exposed business applications first. Advisory AA23-158A documents the exploitation of Accellion FTA in 2020 and 2021, GoAnywhere MFT (CVE-2023-0669) in January 2023 and MOVEit Transfer (CVE-2023-34362) from May 27, 2023, through SQL injection followed by a web shell named LEMURLOOT. In December 2024, Huntress observed exploitation of Cleo Harmony, VLTrader and LexiCom as early as December 3, with a sharp uptick on December 8, and found that the initial patch for CVE-2024-50623 (version 5.8.0.21) was still exploitable. In 2025, Mandiant and GTIG tracked a campaign against Oracle E-Business Suite: exploitation from August 2025, extortion emails from September 29, 2025, and an emergency Oracle patch on October 4, 2025 for CVE-2025-61882.
The common thread: an exposed server, a missing or insufficient patch, and a payload stored where nobody looks, a web shell or, in the EBS case described by Mandiant, a template inserted into the XDO_TEMPLATES_B database table.
What they have done
- MOVEit Transfer, May 2023. Advisory AA23-158A places the start of exploitation on May 27, 2023 and recalls that during the preceding GoAnywhere campaign, the group claimed approximately 130 victims over ten days.
- Cleo, December 2024. Huntress found at least ten businesses whose Cleo servers were compromised, in the consumer products, food, trucking and shipping industries. Clop claimed the campaign to BleepingComputer on December 15, 2024.
- Oracle E-Business Suite, 2025. According to Mandiant and GTIG, the actor sent a high volume of extortion emails from September 29, 2025, providing file listings dating back to mid-August 2025 as proof of theft. The contact addresses had been listed on the Clop leak site since at least May 2025.
What stops them
- Inventory and exposure of third-party applications. Know which file transfer servers and business applications are reachable from the internet, and by whom. ISO 27001:2022 controls 5.9 and 8.8; SOC 2 criterion CC7.1.
- Patch exploited vulnerabilities within days. Track the CISA KEV catalog for exposed products, and do not treat a patch as sufficient until the vendor confirms it, as the Cleo case showed. ISO 27001:2022, 8.8; SOC 2, CC7.1.
- Egress filtering on application servers. Mandiant recommends blocking all non-essential outbound traffic from EBS servers; the same rule applies to any transfer server. A web shell with no way out steals nothing. ISO 27001:2022, 8.20 and 8.22.
- Monitoring of exposed servers. Log and alert on unusual child processes, new files in web directories and reconnaissance commands. SOC 2, CC7.2; ISO 27001:2022, 8.16.
- Segmentation and least privilege. Advisory AA23-158A calls for network segmentation to limit lateral movement; a transfer server has no need to reach the domain controller. ISO 27001:2022, 8.22 and 5.15.
- A response plan for extortion without encryption. Know in advance which data passes through these servers, whom to notify and within what deadline, because there may be no system to restore, only a leak to manage. ISO 27001:2022, 5.24 to 5.26; SOC 2, CC7.4.
Sources
- CISA and FBI, joint advisory AA23-158A: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability (June 2023)
- Google Threat Intelligence Group and Mandiant, Oracle E-Business Suite Zero-Day Exploitation (October 2025)
- Huntress, Cleo Software Actively Being Exploited in the Wild (December 2024, updated January 2025)
- BleepingComputer, Clop ransomware claims responsibility for Cleo data theft attacks (December 15, 2024)
Frequently asked questions
- Does Clop still encrypt systems?
- Less and less. Advisory AA23-158A notes that the group relies mostly on data exfiltration rather than encryption, and the Cleo and Oracle E-Business Suite campaigns described by Huntress and Mandiant were pure data theft. Backups therefore do not protect you here: what matters is knowing which data passes through your exposed servers and detecting when it leaves.
- We use neither MOVEit nor Oracle E-Business Suite. Are we exposed?
- Possibly through a supplier. Clop's model is to exploit a widely deployed product, then extort every organization whose data sat on it, including the data of their customers. The question to ask your critical third parties is simple: which internet-facing file transfer products do they run, and how quickly do they patch a vulnerability that is being exploited?
- What should we do if a supplier reports a Clop-related leak?
- Ask for the exact list of affected files, the date of exploitation and proof of the patch. Run your incident management plan as if these were your own systems: data classification, notification obligations, communications. Do not wait for a leak site post to act, because in the Oracle campaign documented by Mandiant the gap between theft and announcement was measured in weeks.
Let's talk about your compliance program.
Last updated: 2026-09-20
