Desk live·
ForensicPost
Breaches/Mass exploitation/File 25-0217

A Hundred and Eighty-Two Names, Posted in One Go

On 14 February 2025 Cl0p published the victim list from its Cleo campaign. The corpus has eleven files on this group and none on the campaign that produced the list.

Constructed geometry · not a chart of case data
TargetCleo customers
ActorCl0p
D. Kennedy13 min readConfidence: medium4 sources reviewed

Cl0p posted the names of 182 organisations to its leak site on 14 February 2025, the accumulated result of a campaign against Cleo’s managed file-transfer products that began the previous December.

The list had grown in stages. Earlier postings named smaller batches; reporting in December 2024 described the group preparing to name more than sixty.

Two Vulnerabilities, One Of Them A Patch That Did Not Hold

The Cleo campaignVendor advisories and contemporaneous reporting
TimeEventEvidence
October 2024CVE-2024-50623 disclosed — unrestricted file upload and downloadVendor advisory; fixed in 5.8.0.21
December 2024CVE-2024-55956 disclosed — unauthenticated file write to the Autorun directoryVendor advisory; fixed in 5.8.0.24
December 2024Exploitation reported against exposed instances; Cl0p begins naming victimsContemporaneous reporting
14 February 2025182 organisations named on the leak siteContemporaneous reporting

The sequence is the point. A flaw was disclosed and patched in October; a second, related flaw in the same product reached the same outcome in December. An organisation that patched promptly in October was exposed again eight weeks later.

This Is The Fourth Time

The same group has run this campaign against a managed file-transfer product on four occasions across five years, against four different vendors. That pattern is filed separately at 25-0411.

This corpus recorded at 25-0214 that the file-transfer product is a bank’s weakest wall. The Cleo campaign is the general case: the product sits at the edge, holds everything in transit, and is bought by organisations that are not the ones being attacked in the headlines.

The Number Is A Leak-Site Count

It counts organisations the group chose to name, which is not the same as organisations compromised, and both differ from organisations that lost data. The corpus recorded at 25-0511 that a leak-site count measures publication rather than income, and the same applies to victims.

Naming is an extortion instrument. An organisation appears on the list because it did not pay, or paid late, or because listing it puts pressure on somebody else. An organisation absent from the list may have paid.

How we reported this

Compiled from vendor advisories and contemporaneous reporting, listed below. The 182 figure is a leak-site posting count reported at the time and is not a count of confirmed compromises; this desk has not verified the list or contacted the named organisations. The named victims discussed elsewhere in this cluster are those that have publicly confirmed an incident. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Cl0p ransomware group to name over 60 victims of Cleo attackSecurityWeek
  2. Cleo file transfer vulnerabilities — Cl0p’s latest attack vectorSOCRadar
  3. Cleo CVE-2024-50623 and CVE-2024-55956 explainedCybelAngel
  4. Cl0p ransomware hits over 60 companies using Cleo platformCybernews
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary