ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims
|by Alpha Team

ZeroFox Intelligence Flash Report - Cl0p Publishes Data of Cleo Compromise Victims
Product Serial: F-2025-01-20a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the publishing of data allegedly stolen from victims of the Q4 2024 Cleo compromise, by the ransomware and digital extortion collective Cl0p.
Standing Intelligence Requirements

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Between January 17 and 18, 2025, the ransomware group Cl0p published data allegedly belonging to three organizations that were targeted during the Q4 2024 compromise of Cleo secure managed file transfer (MFT) solutions.
- Previously, in December 2024, Cl0p added the obfuscated names of 66 alleged victim organizations to their leak site. The names of these organizations were unveiled on January 14 and 15, 2025, along with a blog post threatening to publish their data on January 18, 2025.
- There is a very likely chance that Cl0p will begin publishing data stolen from other named organizations in the coming weeks, beginning with those that Cl0p perceives to be impeding negotiations or unlikely intending to meet demands.
- Also between January 17 and 18, 2025, Cl0p posted a seemingly-unrelated statement to their victim leaksite, alluding to the collective’s “downloading” of data belonging to organizations that use the MOVEit MFT solution, via a vulnerability. The meaning and intent behind Cl0p’s message to MOVEit customers is unclear.
Tags: dark web, vulnerability/exploit, threat actor, DDW Ransomware