Cl0p
TA505 / FIN11. Specialists in mass zero-day exploitation of managed file-transfer software — MOVEit, GoAnywhere, Cleo — compromising hundreds of organisations in a single campaign.
Claimed victims
570
Top region
US
Top sector
Technology
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2026-09-10 | HENRYPRATT.COM | Manufacturing | US |
| 2026-09-10 | HARLEY-DAVIDSON.COM | Manufacturing | US |
| 2026-08-14 | ZEBRA.COM | Manufacturing | US |
| 2026-08-12 | AOL.COM | Technology | US |
| 2026-08-12 | GATE7LLC.COMGBBEV.COM | Not Found | GB |
| 2026-08-12 | ENTERATEK.MXESBERBEVERAGE.COM | Agriculture and Food Production | MX |
| 2026-08-12 | NUVITIA.COM | Technology | ES |
| 2026-08-12 | IPMSOLUTIONS.SK | Professional Services | SK |
| 2026-08-12 | ECCELLENT.COM | Other | IT |
| 2026-08-12 | STNET.IT | Technology | IT |
Regions targeted
Sectors targeted
Suspected origin
Russia — TA505 / FIN11; Russian-speaking. Attribution reflects open-source consensus, not certainty.
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.