Desk live·
ForensicPost
Ransomware/Aftermath/File 23-0715

ALPHV and Cl0p Both Listed Estee Lauder From Separate Intrusions

ALPHV and Cl0p both listed Estée Lauder in July 2023, from separate intrusions — one of them through MOVEit. Being compromised by one operation confers no protection from another, and the corpus had no prior file saying so.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetThe Estée Lauder Companies
ActorALPHV, Cl0p
S. Rosler11 min readConfidence: medium3 sources reviewed

In July 2023 two ransomware operations, ALPHV — also called BlackCat — and Cl0p, separately listed the Estée Lauder Companies on their leak sites. Reporting describes ALPHV making the company aware of its intrusion on 15 July 2023, and Cl0p’s claim as arising from exploitation of the MOVEit file transfer vulnerability. The company shut down some systems and engaged external experts.

ALPHV is reported to have publicly mocked the company’s security response and claimed to still be present on the network.

Victims Are Not Exclusive

We have argued at 23-0413 that a public vulnerability is shared infrastructure rather than a competitive asset, and that rival operations converge on the same flaw without coordination.

This is that argument at the level of the target. Two operations with no relationship arrived at one company in the same window through different routes, and neither had any reason to defer to the other. An organisation dealing with an incident should not assume it is dealing with an incident.

One Of Them Was The Season’s Vulnerability

The Cl0p claim sits inside the MOVEit campaign we filed at 23-0601, which supplied victims across sectors for months on the strength of one file transfer flaw.

That matters for how the incident reads: one intrusion was a targeted operation against this company, and the other was the company appearing on a list generated by a mass exploitation campaign. They are different events with different implications, and they arrived as one crisis.

The Taunt Is An Operational Claim

An operation stating publicly that it remains on the network is applying pressure, and it may simply be false. It is also the one assertion a victim cannot easily disprove mid-incident.

We have recorded leak-site messaging as choreography at 23-1110 and 22-1104b. This variant targets the decision to declare an incident closed, which is the moment an organisation most wants and least deserves confidence. The same company appears again at 26-0620, breached through a different platform entirely and undetected for ten months — which is the more ordinary way this ends.

How we reported this

Compiled from contemporaneous reporting of the leak-site listings and the company’s public statements, listed below. A figure of 131GB circulated in coverage and was attributed at different points to both operations; because that conflation cannot be resolved from the public record, no volume figure is carried here — which is the principal reason this file is graded medium. No count of affected individuals was published. Claims made by ransomware operations about their own access are recorded as claims. Corrections: corrections@forensicpost.com.

Sources
  1. Estée Lauder beauty giant breached by two ransomware gangsBleepingComputer
  2. Cosmetics Giant Estée Lauder Targeted by Two Ransomware GroupsSecurityWeek
  3. BlackCat and Clop gangs both claim cyber attack on Estée LauderComputer Weekly
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary