Cl0p perfected a model that made ransomware encryption largely unnecessary: find a zero-day in a widely deployed managed file transfer product, exploit every internet-facing instance in a single automated burst, steal the data, and extort the victims.
Managed file transfer products are an unusually good target. Organisations use them precisely because they move sensitive data — HR records, financial reports, health information, legal documents — and because they are often internet-facing by design, connected to many partners, and administered by teams with no security remit.
The May 2023 MOVEit Transfer campaign is the clearest example. Cl0p exploited a SQL injection zero-day across essentially every reachable MOVEit instance over a single holiday weekend. The victim count exceeded 2,700 organisations and the affected-individual count exceeded 90 million, including many organisations that had never heard of MOVEit — it was in use by their payroll processor, benefits administrator, or state agency. The group did not deploy ransomware at all in most cases; encryption would have added nothing to the leverage that possession of the data already provided.
It ran the same play against Accellion FTA in 2020, GoAnywhere MFT in early 2023, and Cleo Harmony and VLTrader in late 2024.
The group is assessed as related to the FIN11 and TA505 clusters, and operates a leak site where victims are published on a schedule if they do not pay. The U.S. State Department has offered a reward of up to $10 million for information on the actors.