home.social

#cl0p — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cl0p, aggregated by home.social.

fetched live
  1. Cl0p Hackers Exploit PTC Windchill Flaw to Steal Passwords and Sensitive Company Data

    Indicators extracted from public reporting. Source: reliaquest.com/blog/clop-retur

    Pulse ID: 6a854563c1a89b92936e12c9
    Pulse Link: otx.alienvault.com/pulse/6a854
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 05:55:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Extortion #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #Password #Passwords #RCE #Word #bot #CyberHunter_NL

  2. Think of it as a subscription to your own R&D department, billed by strangers.

    Your mission, should you choose to accept a mission that is already on fire, is to audit exposure of any technical documentation and IP shared with third-party vendors across your supply chain.

    Reward: You've received the Breadcrumb Trail — a map showing exactly where your IP went. Unfortunately Cl0p has the other copy.

    #Cl0p #Ransomware #DataBreach #CyberSecurity #APT #AchievementUnlocked (2/2)

  3. Oh...and speaking of hackers:
    #Russia linked collective #Cl0p claims to have exfiltrated thousands of gigs of technical materials from #Shell, #Philips, and another 50 companies.

    #Cl0p has an interesting business model. Instead of "lock it down" ransomware, they exfiltrate IP, then hold *it* ransom. Pay them, or trade secrets get dumped. That's a nice patent application you got there...be a shame if it was to become public...

    devdiscourse.com/article/techn

  4. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    Pulse ID: 6a7eaebbd5fc7dde1f816179
    Pulse Link: otx.alienvault.com/pulse/6a7ea
    Pulse Author: Tr1sa111
    Created: 2026-08-14 05:59:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RansomWare #bot #Tr1sa111

  5. Cl0p Ransomware: Attack Pattern in Threat Intelligence

    A comprehensive analysis of Cl0p ransomware operations spanning six years reveals a sophisticated threat actor with systematic focus on managed file transfer infrastructure. The group has exploited zero-day vulnerabilities in nine distinct campaigns targeting platforms including Accellion FTA, SolarWinds Serv-U, Fortra GoAnywhere, MOVEit Transfer, and Oracle E-Business Suite. Cl0p demonstrates exceptional operational discipline through multi-year reconnaissance, strategic Q4 timing coinciding with holidays, and infrastructure diversification across 79 autonomous systems. The group maintains 10-14 month dormancy periods between campaigns, with pre-attack scanning documented up to two years before exploitation. Their success stems from exploiting a fundamental architectural weakness where internet-facing applications coexist with encryption keys within single trust boundaries, rendering encryption-at-rest controls ineffective.

    Pulse ID: 6a7ca263ee7777102409724c
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cl0p #CyberSecurity #Encryption #Holiday #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Rust #SolarWinds #ZeroDay #bot #AlienVault

  6. RE: infosec.exchange/@mle/11701998

    As of ~yesterday, a leak warning has appeared on Cl0p's site for 42 alleged victims of this campaign. Total estimated amount of data stolen across all orgs reaches roughly 23TB and appears to include data like CAD files, databases and backups, engineering drawings, and various other documents.

    Their total estimate of value for the data seems a bit...off, though, considering one org's valuation is listed at over 2 trillion dollars. Without that outlier, the rest of their estimate for company revenue comes to roughly $192 billion. It's in their best interest to provide estimates on the high side, though, so that's an important consideration.

    #security #ransomware #extortion #cl0p

  7. New from me: analysis of a June #Cl0p extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.

    Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors.

    Read more: censys.com/blog/cl0p-targets-w

    #infosec #extortion #ICS #energy

  8. This is a phase-two boss with a global campaign already in motion, and your engineering IP is the loot table.

    Windchill runs the intellectual backbone of industrial civilization. Cl0p knows this. Patch PTC Windchill to the latest version immediately and hunt for indicators of compromise before the second wave.

    Reward: You've received the Scorched Drafting Table — a Legendary trophy nobody wanted to earn.

    #Cl0p #Ransomware #ZeroDay #PTCWindchill #CyberSecurity #CriticalHit (2/2)

  9. Cl0p sfrutta una falla critica in PTC Windchill e FlexPLM: webshell ed estorsioni nella supply chain del manufacturing

    La gang Cl0p, nota per gli attacchi di massa a MOVEit e GoAnywhere, sta ora sfruttando CVE-2026-12569 in PTC Windchill e FlexPLM per compromettere aziende manifatturiere, automotive, aerospaziali e retail. Webshell JSP, furto dati ed estorsioni: analisi tecnica completa con IoC.

    insicurezzadigitale.com/cl0p-s

  10. Among the latest data-breach villains: the Washington Post

    Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”

    That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.

    In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.

    The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.

    Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.

    For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.

    Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.

    That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.

    I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.

    I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.

    So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.

    #Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost
  11. Food and Ag-ISAC reports 82% surge in ransomware attacks as Qilin, Akira and CL0P lead campaigns against sector

    New data from the Food and Agriculture Information Sharing and Analysis Center (Food and Ag-ISAC) shows ra…
    #dining #cooking #diet #food #Food #Akira #Cl0p #DDoS #FoodandAg-ISAC #foodandagriculture #Lynx #play #Qilin #ransomwareattacks
    diningandcooking.com/2510429/f

  12. CW: NSFW

    @darkwebsonar @kkarhan that's a different thing.

    - #cl0p is not #clop!

    @defilerzero does the latter…

  13. Cl0p - or Clop, depending on you talk to - is back targeting Australian companies again with cyber extortion attempts, though at this stage it may all be a bluff.

    #cybersecurity #cl0p #cl0p #cybercrime

    cyberdaily.au/security/13172-e

  14. So for many folks - cancelling their Hilton Honors membership was a way to let the chain know that their handling of the situation in Minneapolis was unacceptable.

    Nice techdirt article and template for those perhaps looking to do the same techdirt.com/2026/01/07/dear-h

    Now it appears that the #Cl0p folks claim to have breached Hilton.com - but have yet to publish any data. After following cl0p in a previous life, my estimate is that they're found some novel way to breach a specific technology that many of these companies have deployed, have been immensely successful in compromising a large number of them, and are now inundated with data that they have to wade through.

    (first detection I am aware of was at 2026-01-25 15:14:45 UTC)

    infosec.exchange/@ransomwatch/

    However - I do have confidence that Hilton will not pay them and the data will [eventually] be published to The Dark Web™. (Or more accurately - probably via BitTorrent)

    (you can point your TOR enabled browser of choice to santat7kpllt6iyvqbr7q4amdv6dzr for any updates - the attached screenshot is from there)

    What that means is that for folks that did cancel their membership is that their data is likely going to be leaked to various and sundry criminal elements and probably lead to increased cyber-type headaches such as spam, phishing and identity theft for anyone involved. (Note that this is also true for anyone who did not cancel their Hilton Honors membership.)

    Going to preface this next bit by indicating that I'm not a lawyer nor do I play one on TV - and that no sane person should take legal advice from me or anyone else who is not a practicing lawyer lest you end up being the star of one of those "sovereign citizen" clips on youtube.

    Now - there probably is a way to help translate at least some of this into pain for the Hilton chain. If you are in the EU - GDPR does provide a lot of leverage for individuals in terms of data and privacy protection. As data breaches are more common - and you do live in Europe - you may already have some tools to point in Hilton's general direction.

    (Of note as well is that the GDPR 72-hour notifications window starts once the company is "aware" of the breach - and there may be some convoluted verbiage on what that actually means, but your report/request as a European person may be what actually starts that clock.)

    If you don't live in Europe - the folks at DLA Piper have a fairly substantial breakdown of breach requirements by country - but may give you some pointers in keywords to be using when communicating with their agents based on your locale.

    dlapiperdataprotection.com/?t=

    Additionally - if you have the time (and patience) to deal with someone on the phone - this is is the sort of inquiry that will need to be escalated to a human (i.e. will cost Hilton money) to answer.

    hilton.com/en/help-center/glob

    You may also want to reach out via any of the emails listed in the techdirt article above

    This may be of some assistance in providing - at the very least - some time and cycle burn for their public relations folks, who are probably also very busy trying to put some spin on some of their other PR disasters.

    Some questions that you may want to ask anyone that you get a hold of via phone, email, or carrier pigeon:

    • Are you aware that the ransomware gang cl0p has claimed that they have breached Hilton.com?
    • Can you confirm that this breach notification is legitimate?
    • Do you have an idea of what data was allegedly stolen, how much and when?
      • Has the vulnerability that led to this alleged breach been identified and remediated?
    • Is there any personally identifiable information (PII) included in the corpus?
    • Is my PII included in that corpus?
    • Is there a plan to notify affected individuals and/or provide remediation or credit monitoring?

    #hhonors #ice #Hilton #USPol #HiltonBoycott #ransomware

  15. Korean Air confirms 30,000 of its employee records have been stolen after the Cl0p ransomware gang leaked the data online, following exploitation of an Oracle EBS vulnerability.

    Read: hackread.com/30000-korean-air-

    #CyberSecurity #DataBreach #Cl0p #KoreanAir #OracleEBS #InfoSec

  16. Barts Health NHS confirms Cl0p ransomware breached its invoicing system by exploiting an Oracle EBS flaw. The organisation is now taking legal action against the notorious Russian-speaking group.

    Read: hackread.com/barts-health-nhs-

    #NHS #Cl0p #Ransomware #DataBreach #CyberSecurity #Oracle