Clop ransomware may have infected even more victims than previously thought

Ransomware attack on a computer
(Image credit: Kaspersky)

When the Clop ransomware gang first revealed it abused a flaw in GoAnwyhwere and stole data from 130 companies, not a lot of people believed them. Especially because at the time, the group only added details from one victim - Health Systems - to its data leak website.

However, as days go by, and Clop keeps on adding more and more victim companies to its website, it just might be that the group was telling the truth from the very start. That still doesn’t mean the number is correct.

The latest victim is the Canadian financing giant Investissement Quebec. Earlier this week, the company confirmed to TechCrunch that “some employee personal information” was taken by the group, after abusing the GoAnywhere vulnerability.

Dozens of victims

Before that, we’ve had dozens of companies added to the leak site, which later confirmed having been breached: Hitachy Energy, Hatch Bank, Rubrik, AvicXchange, Saks Fifth Avenue, Galderma, ITx Companies, Brightline, Emerald Expositions, MedMinder, Onex, the City of Toronto (allegedly, yet unconfirmed), Homewood Health, Guinness Partnership, Avidia Bank, Medex Healthcare, Cornerstone Home Lending, and Grupo Vanti, just being some of them.

TechCrunch says that the group has so far added roughly half of the 130 companies allegedly affected. But that still doesn’t mean the data was stolen, or that it’s valid. Payment software startup AvidXchange, for example, told the media that even though it was listed on Clop’s website (as “coming soon”), it doesn’t store any data on Fortra.

Saks Fifth Avenue said the group only stole “mock data” - placeholder data used by different company departments for training and analysis. “The mock customer data does not include real customer or payment card information and is solely used to simulate customer orders for testing purposes,” said Saks spokesperson Nicola Schoenberg.

Even if the number ends up being smaller than what Clop originally stated, it will still most likely be a lot more than what everyone initially thought. 

Via: TechCrunch

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Cl0p ransomware group says it was behind Cleo attacks
Data leak
US utility giant says MOVEit hack exposed stolen data
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Insurance
Globe Life data breach may have affected 850,000 more patients than previously thought
Latest in Security
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
Latest in News
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
China
Chinese hackers targeting Juniper Networks routers, so patch now