Skip to content

other

Cl0p

Russia-linked ransomware and extortion gang known for mass data-theft campaigns exploiting file-transfer software like MOVEit and Accellion.

Known aliases

  • Cl0p-affiliated operators
  • Cl0p ransomware gang
  • Clop

Relationships

No evidence-backed relationships are recorded.

Current stories

invest3 publishers

Kiteworks asks customers to power down for nine hours to guard against zero-day attacks

Kiteworks told customers to shut its file-transfer servers for nine hours this weekend after a federal warning. The company says its current release fixes every known flaw, so the outage guards against one it does not know about.

Publishers:einpresswire.comheise.detechcrunch.com

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 63%
Investor
Investor 25%

Reality

Evidence60
Adoption50
Hype gap+25
Incentives65
Confidence55
security8 publishers

A Windchill RCE chain that never encrypts anything, and the June hunt window it opens

Suspected Cl0p operators chain a FlexPLM WSDL disclosure to CVE-2026-12569 for unauthenticated code execution. No encryption stage means ransomware-tuned detections stay silent.

Perspective Coverage

8 publishers
Builder
Builder 25%
Operator
Operator 57%
Investor
Investor 18%

Reality

Evidence68
Adoption55
Hype gap−10
Incentives60
Confidence62
security6 publishers

CenterPoint confirms a customer data theft it learned about from a dark web post

CenterPoint Energy's 8-K says an unauthorized party took customer personal information through an external-facing system. The person selling the file says it came out of a public API with no rate limiting.

Perspective Coverage

6 publishers
Builder
Builder 25%
Operator
Operator 54%
Investor
Investor 21%

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives65
Confidence60