
THREAT‑WATCH
Threat Actors
Cl0p
Clop, TA505
A group known for mass-exploiting vulnerabilities in file-transfer and enterprise software to steal data at scale, often without deploying encryption at all.
Cl0p's signature approach is exploiting a single vulnerability in widely used enterprise software to compromise dozens or hundreds of organizations in one campaign, then extorting them over stolen data rather than encrypting systems. Its 2023 mass-exploitation of a MOVEit Transfer vulnerability affected thousands of downstream organizations. In 2026, Cl0p ran a comparable campaign exploiting a vulnerability in PTC's Windchill and FlexPLM product lifecycle management software, naming over 40 organizations including major manufacturers. As of mid-2026, Cl0p remained highly active, with over 1,300 victims claimed on its leak site.
Target Sectors
Any organization using the specific enterprise software being mass-exploited in a given campaign, span across manufacturing, finance, and professional services.