Desk live·
ForensicPost
Breaches/Concentration/File 25-0411

The Fourth File-Transfer Product in Five Years

One group has now run the same campaign against four managed file-transfer vendors. The category keeps being chosen because of what the category is, not because of who makes it.

Constructed geometry · not a chart of case data
TargetFile-transfer estate
ActorCl0p
D. Kennedy13 min readConfidence: medium3 sources reviewed

The Cleo campaign at 25-0217 is the most recent of a series. The same group has previously run the same play against three other managed file-transfer products, in campaigns spanning 2021, 2023 and 2023.

Four vendors, four codebases, four sets of engineers. The constant is not a supplier and it is not a defect class. It is the job the product does.

What A Managed File-Transfer Product Is

It sits at the network edge by design, because its purpose is to receive files from outside. It is authenticated to internal systems, because its purpose is to deliver them inward. And it holds, at any moment, whatever the organisation was in the middle of sending — which in practice is the material that leaves the organisation because it has to.

Payroll files. Claims data. Pension records. Anything moving to a processor, an auditor or a regulator passes through it. A product that is exposed, trusted and full is not an unfortunate combination; it is the specification.

This Is The Concentration Theme, In Its Purest Instance

The corpus argues throughout that the breach happens somewhere the affected person has never heard of. A file-transfer vendor is the extreme case: it has no consumer relationship at all, and the people whose records pass through it could not name it under any circumstances.

The corpus recorded the same structure in payroll at 25-0930b, in claims processing across the insurance files, and at 25-0214 in banking. Each time the affected population is defined by a contract they were not party to.

And It Defeats The Standard Advice

Patch promptly: the Cleo sequence at 25-0217 shows an organisation that patched in October exposed again in December by a related flaw in the same product.

Reduce the attack surface: the product is the attack surface, and removing it means not sending files. Vet your suppliers: four vendors were vetted by hundreds of organisations and it made no difference, because the exposure follows the function rather than the firm.

The corpus recorded at 25-0421b that it over-covers exploitation because a named CVE generates documentation. This file is a case where the CVE is the least interesting part: the vulnerability was replaceable and the position in the architecture was not.

This is an analysis file

It generalises from the Cleo campaign filed at 25-0217 and from the group’s previously reported campaigns against other managed file-transfer products, using the sources listed below. Prior campaigns are referenced by category rather than described in detail, as they fall outside this corpus’s 2025 period. No claim is made about the total number of organisations affected across the series. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Cleo file transfer vulnerabilities — Cl0p’s latest attack vectorSOCRadar
  2. Patch now — Cleo products actively exploited in ransomware attacksGreenbone
  3. Blue Yonder investigating Cl0p ransomware threat linked to exploited Cleo CVEsCybersecurity Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary