Index live· 1,284 files · 148 editions
ForensicPost

Search the index

17 results
Try
Results for “Cl0p”Newest first
25-1003
File

The Oracle Campaign Named Another One

For most of the interval the company was the victim of an incident that had already happened and had not yet surfaced.

Cl0pZero-day exploitationManufacturingExploitation
Sev 4TargetLogitechActorCl0p
25-1110
File

Cl0p Oracle EBS Victim List Spans Schneider Electric, Logitech and Emerson

Automation, mining, peripherals, a newspaper. The vulnerability selected the victims, and the attacker learned afterwards who they were.

Cl0pCVE-2025-61882ManufacturingExtortion
Sev 4TargetOracle EBS customers, multipleActorCl0pUSA
25-1017
File

Envoy Air Confirms It Was Caught in the Cl0p Oracle EBS Campaign

A subsidiary carries the parent’s brand and data relationships, frequently with a fraction of its security capability.

Cl0pCVE-2025-61882LogisticsAviation
Sev 3TargetEnvoy AirActorCl0pUSA
25-1016
File

Washington Post Named Among Oracle EBS Extortion Victims

Nobody targeted a newsroom. A media organisation cannot scope its security to the systems that obviously hold journalism.

Cl0pCVE-2025-61882MultipleMedia
Sev 3TargetThe Washington PostActorCl0p
25-1012
File

A University’s Finance System, 1.3 Terabytes, and a Leak-Site Listing

A university ERP holds staff, students, alumni donors and grant administration. One flaw reached all of it.

Cl0pCVE-2025-61882EducationEducation
Sev 4TargetHarvard UniversityActorCl0p
25-1007
File

One Enterprise Application, Victims on Four Continents

The window between disclosure and exploitation is shortest exactly where the ability to respond is slowest.

Cl0pMass exploitationMultipleExploitation
Sev 5TargetOracle enterprise estatesActorCl0pSouth Korea
25-0930
File

One Zero-Day, Twenty-Nine Named Victims, No Encryption

One ERP zero-day, 29 named victims across unrelated sectors, nothing encrypted. Theft-and-publication at industrial scale.

Cl0pCVE-2025-61882MultipleExtortion
Sev 5TargetOracle EBS deploymentsActorCl0p
25-0411
File

The Fourth File-Transfer Product in Five Years

A product that is exposed, trusted and full is not an unfortunate combination. It is the specification.

Cl0pEdge product exploitationMultipleConcentration
Sev 5TargetFile-transfer estateActorCl0p
25-0403
File

Hertz Confirms Customer and Employee Data Taken Through Cleo Flaw

A privately held operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.

Cl0pSupplier product exploitationTravelDisclosure
Sev 4TargetHertzActorCl0pUSA
25-0217
File

A Hundred and Eighty-Two Names, Posted in One Go

An organisation appears on the list because it did not pay, or paid late. An organisation absent from the list may have paid.

Cl0pEdge product exploitationMultipleMass exploitation
Sev 4TargetCleo customersActorCl0p
23-1117
File

Welltok Notified 8.5 Million People Over MOVEit, Then the Number Nearly Doubled

An initial figure measures how far a review had got, not how large an incident was.

Cl0pSQL injectionHealthcareHealthcare
Sev 5TargetWelltokActorCl0pUSA
23-0728
File

Maximus Says the MOVEit Flaw Reached Health Data for up to 11 Million People

The campaign is unmeasurable. Its individual victims are not.

Cl0pSQL injectionHealthcareHealthcare
Sev 5TargetMaximusActorCl0pUSA
23-0715
File

ALPHV and Cl0p Both Listed Estee Lauder From Separate Intrusions

An organisation dealing with an incident should not assume it is dealing with an incident.

ALPHV, Cl0pMOVEit (Cl0p); not established (ALPHV)RetailAftermath
Sev 4TargetThe Estée Lauder CompaniesActorALPHV, Cl0pUSA
23-0601
File

CISA and FBI Say Cl0p Exploited a MOVEit Zero-Day to Steal Transfer Databases

A product bought to move sensitive files safely became the reason thousands of organisations lost them at once.

Cl0pSQL injectionMultipleThird party
Sev 5TargetMOVEit Transfer customersActorCl0pUSA
23-0601b
File

MOVEit Reached Oregon and Louisiana Motor Vehicle Records for 9.5 Million People

Every other consumer file here involves someone who chose a company. Here the population is everyone who needed to drive.

Cl0pSQL injectionPublic sectorPublic sector
Sev 5TargetOregon DMV and Louisiana OMVActorCl0pUSA
23-0413
File

Cl0p and LockBit Both Exploited PaperCut a Month After the Patch Shipped

High privilege, low attention, reachable. The vulnerable thing is rarely the one anyone would name.

Cl0p, LockBitCVE-2023-27350TechnologyExploitation
Sev 4TargetPaperCut MF/NG operatorsActorCl0p, LockBitUSA
23-0203
File

Cl0p Exploited a GoAnywhere MFT Zero-Day Four Months Before MOVEit

The same operators, the same product category, four months before MOVEit. The rehearsal nobody treated as one.

Cl0pCommand injectionMultipleThird party
Sev 5TargetGoAnywhere MFT customersActorCl0p
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging