In July 2023 two ransomware operations, ALPHV — also called BlackCat — and Cl0p, separately listed the Estée Lauder Companies on their leak sites. Reporting describes ALPHV making the company aware of its intrusion on 15 July 2023, and Cl0p’s claim as arising from exploitation of the MOVEit file transfer vulnerability. The company shut down some systems and engaged external experts.
ALPHV is reported to have publicly mocked the company’s security response and claimed to still be present on the network.
Victims Are Not Exclusive
We have argued at 23-0413 that a public vulnerability is shared infrastructure rather than a competitive asset, and that rival operations converge on the same flaw without coordination.
This is that argument at the level of the target. Two operations with no relationship arrived at one company in the same window through different routes, and neither had any reason to defer to the other. An organisation dealing with an incident should not assume it is dealing with an incident.
One Of Them Was The Season’s Vulnerability
The Cl0p claim sits inside the MOVEit campaign we filed at 23-0601, which supplied victims across sectors for months on the strength of one file transfer flaw.
That matters for how the incident reads: one intrusion was a targeted operation against this company, and the other was the company appearing on a list generated by a mass exploitation campaign. They are different events with different implications, and they arrived as one crisis.
The Taunt Is An Operational Claim
An operation stating publicly that it remains on the network is applying pressure, and it may simply be false. It is also the one assertion a victim cannot easily disprove mid-incident.
We have recorded leak-site messaging as choreography at 23-1110 and 22-1104b. This variant targets the decision to declare an incident closed, which is the moment an organisation most wants and least deserves confidence. The same company appears again at 26-0620, breached through a different platform entirely and undetected for ten months — which is the more ordinary way this ends.
Compiled from contemporaneous reporting of the leak-site listings and the company’s public statements, listed below. A figure of 131GB circulated in coverage and was attributed at different points to both operations; because that conflation cannot be resolved from the public record, no volume figure is carried here — which is the principal reason this file is graded medium. No count of affected individuals was published. Claims made by ransomware operations about their own access are recorded as claims. Corrections: corrections@forensicpost.com.