Skip to content

🇷🇺 Cl0p

Threat-actor battle card · maintained from public sources · last updated 2026-08-19 · also known as Clop, TA505, FIN11, Snakefly, Graceful Spider

CategoryRansomware / Data Extortion
AttributionRussia-linked criminal collective TA505/FIN11; no confirmed state affiliation or public indictment
First seen2019-02
StatusActive
Victims L3M
Victims YTD160+ (Oracle EBS 103+ through Q1 2026; Cleo 97+ extortion wave; PTC Windchill/FlexPLM campaign 44+ named victims Q2–Q3 2026 incl. Shell, Philips, GE, FIS Global, Zebra Technologies, Fiserv)
Primary targetsFinancial services, Healthcare, Manufacturing, Industrial/Engineering, Supply chain/logistics, Technology, Education, Media, Food & Agriculture

Overview

Cl0p (also written Clop) is a Russian-linked data extortion group that emerged in February 2019 as a RaaS ransomware variant evolved from the CryptoMix family. Operated by the TA505 collective (also tracked as FIN11, Snakefly, Graceful Spider), Cl0p pioneered the model of exploiting zero-day vulnerabilities in widely deployed enterprise file-transfer and ERP platforms for mass data theft — targeting thousands of organizations simultaneously through a single vulnerability. Over 1,025 confirmed victims and $500M+ in extorted payments since 2019. Active in 2026 through two overlapping campaigns: residual Cleo file-transfer exploitation (Dec 2024 zero-day; 97+ extortion waves through Q1 2026) and an Oracle E-Business Suite campaign (CVE-2025-61882, CVSS 9.8; exploitation began August 2025; 234+ claimed victims, 103 named on DLS as of early 2026). Food and Agriculture sector targeting emerged as a notable Q1 2026 trend: Cl0p accounted for 9.3% of food/ag attacks globally vs. a 4.2% sector baseline, per Food and Ag-ISAC analysis — consistent with the group's indiscriminate mass-exploitation model reaching ERP deployments in the agri-food supply chain.

Tradecraft

  • Zero-day mass exploitation of enterprise file-transfer and ERP platforms: Accellion FTA (2020), SolarWinds Serv-U (2021), GoAnywhere MFT (2023), MOVEit Transfer (2023), Cleo MFT (2024), Oracle E-Business Suite (2025).
  • Pure data exfiltration without encryption in recent campaigns — no encryption payload, focus entirely on exfiltration and extortion leverage.
  • Quadruple extortion: (1) threat of DLS publication; (2) personal email to victim executives and board; (3) direct contact to victim's customers; (4) selling stolen data to third parties if ransom refused.
  • Initial access historically via spear-phishing (SDBot + FlawedAmmy RAT); pivot to zero-day exploitation for mass campaigns since 2020.
  • Cobalt Strike for C2 in legacy operations; recent campaigns are primarily network-level exploitation with no persistent implant required.
  • Exploits vulnerabilities 1–2 months before public disclosure and patch (CVE-2025-61882: exploited from August 2025; patches released September/October 2025).
  • Ransom demands reach $50M (Oracle EBS campaign); seven- and eight-figure demands documented.

Notable victims

  • PTC Windchill/FlexPLM campaign (2026): Shell (investigating, 89GB engineering data claimed), Philips (confirmed compromise of specific enterprise server), General Electric, FIS Global (874GB claimed), Zebra Technologies (8TB claimed — largest volume in campaign), Fiserv (denies customer data compromise), and 38+ additional organizations named on DLS. Exploitation of CVE-2026-12569 (CVSS 9.3) via JSP webshells since early June 2026; data exfiltration-only (no encryption). 44+ named victims across industrial, financial, technology, and energy sectors as of August 2026.
  • Oracle EBS campaign (2025–2026): Logitech, The Washington Post, Cox Enterprises, Pan American Silver, LKQ Corporation, GlobalLogic (Hitachi subsidiary), Barts Health NHS Trust (London), University of Phoenix (3.5M individuals), Copeland, Schneider Electric; 103+ organizations named on DLS, 77 datasets released via torrent.
  • MOVEit (2023): British Airways, BBC, Boots, Shell, US Department of Energy, multiple US state governments; est. 2,000+ organizations affected globally.
  • GoAnywhere MFT (2023): Procter & Gamble, City of Toronto, Hitachi Energy, Community Health Systems.
  • Cleo MFT (2024–2026): 97+ victims in extortion wave continuing through Q1 2026.

Assessment

Cl0p's operational model — stockpiling zero-days in enterprise platforms used for bulk data processing — makes it episodically devastating at a scale no individual target can anticipate or prevent. The PTC Windchill/FlexPLM campaign (CVE-2026-12569, exploited since early June 2026) is the group's most significant wave since MOVEit 2023 by victim count and sector breadth: 44+ named organizations across industrial (Shell, GE, Zebra Technologies), financial technology (FIS Global, Fiserv), healthcare technology (Philips), and others. The campaign's focus on PLM platforms — which hold CAD files, engineering drawings, proprietary manufacturing data, and product R&D — represents a deliberate pivot to high-value industrial IP exfiltration, potentially enabling follow-on economic espionage or sale to state actors. Best enterprise mitigations: isolate PTC Windchill/FlexPLM from internet-facing networks, monitor for large outbound exfiltration via JSP execution, and maintain tested incident-response playbooks. Episodes are typically separated by months of apparent inactivity before the next zero-day campaign surfaces; this campaign is active as of August 2026.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

August 2026

Aug 18 Zebra Technologies Clop Extortion · Technology / RFID and Barcode Solutions · USA Clop listed Zebra Technologies (ZEBRA.COM; global provider of RFID, barcode, and enterprise mobile computing solutions; ~.6B annual revenue) on its DLS around August 18, 2026, claiming exfiltration of 8TB of sensitive data including critical databases and CAD files, consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569). 8TB would be the largest single-organization claim in this campaign. DLS claim — extent of access and veracity unverified. · Sources: https://www.dexpose.io/clop-ransomware-targets-zebra-com-in-major-data-breach/
Aug 13 Shell Clop Extortion · Energy · NLD Clop listed Shell on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 89GB of engineering drawings, facility scans, test reports and project plans. Shell confirmed it is investigating a potential incident. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 13 Philips Clop Extortion · Healthcare Technology · NLD Clop listed Philips on DLS in mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed 13.5GB of PDF drawings, diagrams and blueprints. Philips confirmed an investigation is underway. DLS claim — breach not confirmed. · Sources: https://www.technadu.com/shell-and-philips-confirm-investigation-following-cl0p-data-theft-claims-targeting-nearly-50-companies-including-fiserv-and-ge/633182/
Aug 13 General Electric Clop Extortion · Industrial / Aerospace · USA Clop listed GE on DLS as part of mass PTC Windchill/FlexPLM campaign (CVE-2026-12569); claimed engineering data. GE has made no public statement. DLS claim — breach not confirmed. · Sources: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
Aug 12 Fiserv Clop Extortion · Financial Technology · US Clop DLS claim August 12, 2026 against Fiserv (global fintech/payments processor); scope unconfirmed; first appeared in tracker August 14. · Sources: https://www.bleepingcomputer.com/news/security/
Aug 05 FIS Global Clop Extortion · Financial Technology / Payment Infrastructure · USA Clop listed FIS Global (one of the world's largest financial technology providers, serving thousands of financial institutions) on its DLS on Aug 5, claiming 874GB of exfiltrated data including project files, CAD files, and Windchill-related engineering data — consistent with the PTC Windchill/FlexPLM campaign (CVE-2026-12569) that also hit Shell, GE, Philips, and Fiserv. FIS has not confirmed breach. DLS claim only — unverified. · Sources: https://malware.news/t/clop-ransomware-targets-fis-global/124620

July 2026

Jul 22 Estee Lauder Clop Extortion · consumer/cosmetics · US Clop exploited Oracle E-Business Suite zero-day CVE-2025-61882 to access EL HR systems (attack Aug 9 2025, discovered Jun 19 2026, disclosed via CA AG filing Jul 22 2026); exposed SSNs, passport numbers, bank account details, health info, payroll and performance data for employees; 24 months Kroll identity monitoring offered · Sources: https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/

← All threat actors · Full victim database →