Skip to content
You can now search across every topic, entity and event.What's new
Clop
Organisation

Clop

Clop is a mass-exploitation extortion crew behind the 2023 MOVEit campaign.

Last refreshed: 24 July 2026 · Appears in 1 active topic

Timeline for Clop

#11 23 Jul

Mentioned in: Zimbra preview leaks mail to Russia

Cybersecurity: Threats and Defences
#11 15 Jul

Mentioned in: Oracle EBS gets a 3-day patch clock

Cybersecurity: Threats and Defences
View full timeline →

Background

Oracle E-Business Suite's addition to CISA's Known Exploited Vulnerabilities catalogue this fortnight carried extra weight because of Clop's history: the crew behind 2023's mass exploitation of MOVEit Transfer, a data-theft campaign rather than a ransomware-encryption one, that hit hundreds of organisations worldwide. CISA gave Oracle EBS's privilege-management flaw CVE-2026-46817 a three-day patch Deadline, the same compressed window it reserves for flaws it expects attackers to mass-exploit fast.

Clop, also written Cl0p, is an extortion group tracked since 2019 and linked to the wider TA505/FIN11 cluster. Its signature method is exploiting a zero-day in widely used enterprise file-transfer or ERP software, stealing data at scale before patches land, then extorting victims with the threat of publishing it rather than encrypting their systems. The 2023 MOVEit campaign, run through CVE-2023-34362, is the group's best-known operation.

A KEV listing on software with a Clop lineage now functions as an early-warning signal for defenders: the group's pattern is to strike enterprise platforms broadly before patching catches up, which is why analysts read the Oracle EBS Deadline as a ransomware-adjacent risk rather than routine housekeeping.

Common Questions
What is Clop ransomware?
Clop (also written Cl0p) is an extortion crew active since 2019 that exploits zero-day flaws in enterprise file-transfer or ERP software to steal data at scale, then extorts victims rather than encrypting their systems.Source: Lowdown
Did Clop exploit MOVEit?
Yes. In May 2023 Clop exploited a zero-day SQL-injection flaw, CVE-2023-34362, in Progress Software's MOVEit Transfer product, stealing data from hundreds of organisations worldwide.Source: Lowdown
Why does Oracle E-Business Suite's KEV listing mention Clop?
CISA gave the Oracle E-Business Suite flaw a three-day patch Deadline because the platform carries a Clop mass-exploitation history, the same crew behind the 2023 MOVEit campaign, making a listing read as an early ransomware-adjacent warning.Source: Lowdown