
Clop
Clop is a mass-exploitation extortion crew behind the 2023 MOVEit campaign.
Last refreshed: 24 July 2026 · Appears in 1 active topic
Timeline for Clop
Mentioned in: Zimbra preview leaks mail to Russia
Cybersecurity: Threats and DefencesMentioned in: Oracle EBS gets a 3-day patch clock
Cybersecurity: Threats and DefencesBackground
Oracle E-Business Suite's addition to CISA's Known Exploited Vulnerabilities catalogue this fortnight carried extra weight because of Clop's history: the crew behind 2023's mass exploitation of MOVEit Transfer, a data-theft campaign rather than a ransomware-encryption one, that hit hundreds of organisations worldwide. CISA gave Oracle EBS's privilege-management flaw CVE-2026-46817 a three-day patch Deadline, the same compressed window it reserves for flaws it expects attackers to mass-exploit fast.
Clop, also written Cl0p, is an extortion group tracked since 2019 and linked to the wider TA505/FIN11 cluster. Its signature method is exploiting a zero-day in widely used enterprise file-transfer or ERP software, stealing data at scale before patches land, then extorting victims with the threat of publishing it rather than encrypting their systems. The 2023 MOVEit campaign, run through CVE-2023-34362, is the group's best-known operation.
A KEV listing on software with a Clop lineage now functions as an early-warning signal for defenders: the group's pattern is to strike enterprise platforms broadly before patching catches up, which is why analysts read the Oracle EBS Deadline as a ransomware-adjacent risk rather than routine housekeeping.