Cl0p posted the names of 182 organisations to its leak site on 14 February 2025, the accumulated result of a campaign against Cleo’s managed file-transfer products that began the previous December.
The list had grown in stages. Earlier postings named smaller batches; reporting in December 2024 described the group preparing to name more than sixty.
Two Vulnerabilities, One Of Them A Patch That Did Not Hold
The sequence is the point. A flaw was disclosed and patched in October; a second, related flaw in the same product reached the same outcome in December. An organisation that patched promptly in October was exposed again eight weeks later.
This Is The Fourth Time
The same group has run this campaign against a managed file-transfer product on four occasions across five years, against four different vendors. That pattern is filed separately at 25-0411.
This corpus recorded at 25-0214 that the file-transfer product is a bank’s weakest wall. The Cleo campaign is the general case: the product sits at the edge, holds everything in transit, and is bought by organisations that are not the ones being attacked in the headlines.
The Number Is A Leak-Site Count
It counts organisations the group chose to name, which is not the same as organisations compromised, and both differ from organisations that lost data. The corpus recorded at 25-0511 that a leak-site count measures publication rather than income, and the same applies to victims.
Naming is an extortion instrument. An organisation appears on the list because it did not pay, or paid late, or because listing it puts pressure on somebody else. An organisation absent from the list may have paid.
Compiled from vendor advisories and contemporaneous reporting, listed below. The 182 figure is a leak-site posting count reported at the time and is not a count of confirmed compromises; this desk has not verified the list or contacted the named organisations. The named victims discussed elsewhere in this cluster are those that have publicly confirmed an incident. Graded medium. Corrections: corrections@forensicpost.com.