zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims

Product Serial: F-2025-01-20a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on the publishing of data allegedly stolen from victims of the Q4 2024 Cleo compromise, by the ransomware and digital extortion collective Cl0p.

Standing Intelligence Requirements

DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • Between January 17 and 18, 2025, the ransomware group Cl0p published data allegedly belonging to three organizations that were targeted during the Q4 2024 compromise of Cleo secure managed file transfer (MFT) solutions.
  • Previously, in December 2024, Cl0p added the obfuscated names of 66 alleged victim organizations to their leak site. The names of these organizations were unveiled on January 14 and 15, 2025, along with a blog post threatening to publish their data on January 18, 2025.
  • There is a very likely chance that Cl0p will begin publishing data stolen from other named organizations in the coming weeks, beginning with those that Cl0p perceives to be impeding negotiations or unlikely intending to meet demands.
  • Also between January 17 and 18, 2025, Cl0p posted a seemingly-unrelated statement to their victim leaksite, alluding to the collective’s “downloading” of data belonging to organizations that use the MOVEit MFT solution, via a vulnerability. The meaning and intent behind Cl0p’s message to MOVEit customers is unclear.

Tags: dark web,  vulnerability/exploit,  threat actor, DDW Ransomware