Clop
Profile
Clop is a financially motivated ransomware group active since 2019, known for combining system encryption with large-scale data theft and follow-up extortion. Its most distinctive trait is the exploitation of vulnerabilities in managed file transfer platforms: in 2023 it compromised numerous large organisations through flaws in MOVEit Transfer and MOVEit Cloud. Its victims span sectors such as education and healthcare, with a notable concentration in the United States. Recent incidents include the December 2025 attack on the University of Phoenix, which affected nearly 3.5 million people.
Active since: 2019
Initial access
- Exploitation of vulnerabilities in managed file transfer platforms (MOVEit Transfer and MOVEit Cloud)
Tools
Clop ransomware (system encryption and data-leak extortion)
What defenders should watch
- Prioritise inventory, internet exposure review and prompt patching of file transfer platforms (MOVEit Transfer/Cloud and equivalents), historically the group's preferred vector.
- Monitor abnormal data egress volumes from file transfer servers to external destinations: the main impact is usually data theft rather than encryption alone.
- Education and healthcare organisations, particularly in the United States, are among the observed targets and should review incident response and personal data breach notification plans.
- For incidents involving mass exfiltration (such as the December 2025 case affecting 3.5 million people), having pre-agreed communication procedures for affected individuals and regulators significantly reduces impact.
Most affected countries
- United States4
- United Kingdom3
- India3
- Switzerland2
- Finland2
- Australia2
- Canada2
- Italy2
Most affected sectors
- Other47
- Technology19
- Manufacturing16
- Retail9
- Transport & logistics4
- Energy & utilities3
- Education3
- Finance & insurance3
Recent victims
| Organisation | Country | Sector | Claimed | Status |
|---|---|---|---|---|
| Aldo Group | Canada | Retail | 9/23/2026 | ◌ Claimed (unverified) |
| Brillon Consumer | — | Retail | 9/23/2026 | ◌ Claimed (unverified) |
| Suunto | Finland | Retail | 9/23/2026 | ◌ Claimed (unverified) |
| SMAP Center | Ukraine | Education | 9/23/2026 | ◌ Claimed (unverified) |
| DAD Co. | Thailand | Other | 9/23/2026 | ◌ Claimed (unverified) |
| Clearway Group | — | Technology | 9/23/2026 | ◌ Claimed (unverified) |
| Hodero Holdings Ltd | — | Other | 9/23/2026 | ◌ Claimed (unverified) |
| 🔒 Sitio web | — | Other | 9/23/2026 | ◌ Claimed (unverified) |
| 🔒 Organización (CA) | Canada | Other | 9/23/2026 | ◌ Claimed (unverified) |
| Brinks | New Zealand | Transport & logistics | 9/23/2026 | ◌ Claimed (unverified) |
| Saul | United Kingdom | Other | 9/23/2026 | ◌ Claimed (unverified) |
| 🔒 Organización (OM) | Oman | Other | 9/23/2026 | ◌ Claimed (unverified) |
| Infinigate | Switzerland | Technology | 9/23/2026 | ◌ Claimed (unverified) |
| Sweet Lake Land and Oil Co Inc | — | Energy & utilities | 9/23/2026 | ◌ Claimed (unverified) |
| Kirkland and Ellis | — | Legal | 9/23/2026 | ◌ Claimed (unverified) |
| 🔒 Organización | — | Other | 9/23/2026 | ◌ Claimed (unverified) |
| Columbia Bank | United States | Finance & insurance | 9/23/2026 | ◌ Claimed (unverified) |
| Universidad de La Salle | Colombia | Education | 9/23/2026 | ◌ Claimed (unverified) |
| Valley Truck and Tractor | — | Transport & logistics | 9/23/2026 | ◌ Claimed (unverified) |
| KSS Architects LLP | — | Legal | 9/23/2026 | ◌ Claimed (unverified) |
| Elandretail.com Kmall24.com | — | Retail | 9/23/2026 | ◌ Claimed (unverified) |
| Transport NSW | Australia | Government | 9/23/2026 | ◌ Claimed (unverified) |
| Amey Co. | United Kingdom | Construction | 9/23/2026 | ◌ Claimed (unverified) |
| Henry Pratt | United States | Manufacturing | 9/9/2026 | ◌ Claimed (unverified) |
| Harley-Davidson | United States | Manufacturing | 9/9/2026 | ◌ Claimed (unverified) |
Sources analysed
- ShinyHunters Claim Hack of Rival Ransomware Gang Clop (Infosecurity Magazine, 9/21/2026)
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, GDELT.