← All ransomware groups
Clop logo

Ransomware group profile · #4 by claimed victims

Clop ransomwarealso Cl0p

The ransomware group known as Cl0p is a variant of a previously known strain dubbed CryptoMix. It is worth noting that this variant was delivered as the final payload in a phishing campaign in 2019 and was exclusively financially motivated, with attacks carried out by the threat actors TA505.<br> <br> At that time, malicious actors sent phishing emails that led to a macro-enabled document that would drop a loader called 'Get2.' After gaining an initial foothold in the system or infrastructure, the actors began using reconnaissance, lateral movement, and exfiltration techniques to prepare for the deployment of the ransomware.<br> <br> After the execution of the ransomware, Cl0p appends the extension '.clop' to the end of files, or other types of extensions such as '.CIIp, .Cllp, and .C_L_O_P,' as well as different versions of the ransom note that were also observed after encryption. Depending on the variant, any of the ransom text files were created with names like 'ClopReadMe.txt, README_README.txt, Cl0pReadMe.txt, and READ_ME_!!!.TXT.'<br> <br> The Clop operation has shifted from delivering its final payload via phishing and has begun initiating attacks using vulnerabilities that resulted in the exploitation and infection of victims' infrastructures.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Active First seen Mar 2020
1,344Victims claimed on leak sites
4Victims in the last 30 days
90Victims in the last 90 days
58Countries hit
11Leak-site URLs tracked, 0 online
10 Sep 2026Latest claim recorded

Victimology

Who Clop claims to have breached, from 1,344 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 13OctNov 2025: 98Dec 2025: 1Jan 2026: 46JanFeb 2026: 79Mar 2026: 2Apr 2026: 0AprMay 2026: 2Jun 2026: 0Jul 2026: 1JulAug 2026: 85Sep 2026: 4

Top sectors

Technology246
Professional Services217
Retail & E-Commerce184
Manufacturing160
Transportation97
Financial Services90
Healthcare76
Education46

Top countries

United States455
Canada55
United Kingdom32
Australia25
Germany23
India19
France16
Japan15

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
HENRYPRATT.COM henrypratt.com Manufacturing US 10 Sep 2026
HARLEY-DAVIDSON.COM harley-davidson.com Manufacturing US 10 Sep 2026
HENRYPRATT.COM 10 Sep 2026
HARLEY-DAVIDSON.COM 10 Sep 2026
ZEBRA.COM zebra.com Manufacturing US 14 Aug 2026
NUVITIA.COM nuvitia.com Technology ES 12 Aug 2026
IPMSOLUTIONS.SK ipmsolutions.sk Professional Services SK 12 Aug 2026
ECCELLENT.COM eccellent.com Other IT 12 Aug 2026
STNET.IT stnet.it Technology IT 12 Aug 2026
QCPL.IN qcpl.in Manufacturing IN 12 Aug 2026
FLUIDLOGIC.COM fluidlogic.com Technology US 12 Aug 2026
MIDLANDIND.COM.AU midlandind.com.au Manufacturing AU 12 Aug 2026

All 1,344 Clop victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Clop is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Clop ransomware still active?
Clop is tracked as active. The most recent leak-site claim VULONE recorded is dated 10 September 2026. 4 victims were claimed in the last 30 days.
How many victims has Clop claimed?
VULONE has recorded 1,344 leak-site victim claims attributed to Clop since March 2020, across 58 countries and 14 sectors.
Which industries does Clop target?
The sectors most often named on the Clop leak site are Technology, Professional Services, Retail & E-Commerce.
Which countries are most affected by Clop?
Most Clop victims recorded by VULONE are located in United States, Canada, United Kingdom.
Where does VULONE get Clop victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].