Ransomware dossier

Cl0p

TA505 / FIN11. Specialists in mass zero-day exploitation of managed file-transfer software — MOVEit, GoAnywhere, Cleo — compromising hundreds of organisations in a single campaign.

Claimed victims

570

Top region

US

Top sector

Technology

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-09-10HENRYPRATT.COMManufacturingUS
2026-09-10HARLEY-DAVIDSON.COMManufacturingUS
2026-08-14ZEBRA.COMManufacturingUS
2026-08-12AOL.COMTechnologyUS
2026-08-12GATE7LLC.COMGBBEV.COMNot FoundGB
2026-08-12ENTERATEK.MXESBERBEVERAGE.COMAgriculture and Food ProductionMX
2026-08-12NUVITIA.COMTechnologyES
2026-08-12IPMSOLUTIONS.SKProfessional ServicesSK
2026-08-12ECCELLENT.COMOtherIT
2026-08-12STNET.ITTechnologyIT

Regions targeted

US 26IN 4GB 3IT 3CN 2MX 2PE 1TW 1

Sectors targeted

Technology 15Retail & E-Commerce 8Manufacturing 7Financial Services 5Healthcare 4Professional Services 3

Suspected origin

Russia — TA505 / FIN11; Russian-speaking. Attribution reflects open-source consensus, not certainty.

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups