Millions of employee records associated with major corporations were published on BreachForums by a user calling themselves Nam3L3ss, according to a December 2024 report linking the disclosures to Clop’s 2023 MOVEit Transfer attacks rather than newly reported intrusions. The datasets reportedly included more than 12 million Jones Lang LaSalle records, alongside records associated with Koch Industries, Bank of America, Xerox, Morgan Stanley, Brown-Forman, and Medibank. Exposed information included employee contact details, job titles, departments, and internal identifiers, increasing risks of targeted phishing, identity theft, and corporate espionage. Nam3L3ss denied direct affiliation with Clop and claimed to be redistributing previously stolen information to highlight corporate security failures.
Clop exploited the MOVEit Transfer zero-day CVE-2023-34362 beginning in May 2023, stealing data for extortion without encrypting victims’ systems. The group required victims to initiate negotiations, began publicly naming organizations in June, and had named roughly 260 organizations by mid-August. Its subsequent use of clear-web sites and torrents made stolen files easier to redistribute, extending exposure beyond the initial campaign. The operation followed attacks against Accellion and GoAnywhere file-transfer products and reflected a broader shift toward data-theft-only extortion against large enterprises; Coveware reported that many GoAnywhere victims refused to pay for leak suppression. Organizations should assess both direct and third-party exposure, preserve incident evidence, monitor for employee-data abuse, and strengthen phishing defenses. Patching file-transfer systems, restricting public access, and maintaining asset inventories reduce future compromise risk but cannot retract already stolen data.

See which actors are running it and whether you're in range.
31 events from the most recent confirmed update back to the earliest known activity.
Nam3L3ss published internal records associated with Amazon, HSBC, MetLife, Cardinal Health, HP, Lenovo, and McDonald’s. The disclosures were linked to previously stolen data rather than newly reported intrusions.
Clop published a statement saying some affected organizations had not contacted it to negotiate. It threatened to release data on August 15 from remaining named victims that had failed to contact the group.
Clop publicly named 12 MOVEit victims, predominantly in the United States, with others in Switzerland, Canada, Belgium, and Germany. No victim data was observed leaking at that time.
Clop announced on its leak site that it had stolen data from hundreds of organizations and demanded that victims initiate negotiations by June 14. It threatened publication for organizations that failed to contact it or whose negotiations were unproductive.
Clop claimed responsibility for attacks exploiting CVE-2023-34362 and said exploitation began on May 27. The group initially stated that it had not yet begun extorting victims.
Clop claimed in mid-June that it had deleted stolen MOVEit data belonging to governments, cities, and police services. The source did not verify that the deletion occurred.
ReliaQuest published a blog highlighting the critical MOVEit file-transfer vulnerability later identified in the campaign as CVE-2023-34362.
Progress Software disclosed the MOVEit situation four days after Sophos first observed exploitation on May 27.
Sophos first observed exploitation of CVE-2023-34362 on May 27, matching Clop’s subsequently claimed start date. The campaign used vulnerable MOVEit Transfer systems to steal organizational data for extortion.
Sophos observed Clop exploiting vulnerable PaperCut servers and installing Truebot, malware also used in the GoAnywhere attacks.
Clop published nearly 100 organizations on its leak site following its February GoAnywhere exploitation campaign.
Clop claimed responsibility for more than 130 attacks exploiting Fortra GoAnywhere MFT vulnerability CVE-2023-0669. The group claimed to have stolen terabytes of data for extortion rather than encrypting victims’ systems.
Clop exploited zero-day vulnerabilities in Accellion’s legacy file-transfer application and stole data from more than 100 companies. The resulting extortion campaign continued into 2021.
Clop issued a ransomware demand exceeding $20 million against Software AG, described by Sophos as the first known demand above that amount.
Clop was first observed using phishing, brute-force attacks, and exploitation of known vulnerabilities to compromise organizations.
Nam3L3ss posted datasets on BreachForums associated with JLL, Koch Industries, Bank of America, Xerox, Morgan Stanley, Brown-Forman, and Medibank, including 12,352,524 JLL records. The report linked the employee information to the 2023 Clop MOVEit attacks rather than new compromises.
The report states that the authenticity of the Amazon records previously published by Nam3L3ss was confirmed, without specifying when the confirmation occurred.
The report identifies 25 organizations whose employee directories were published by Nam3L3ss, including previously unlisted victims Fidelity, U.S. Bank, Canada Post, Delta Air Lines, and Applied Materials. Their datasets reportedly contain 124,464, 114,076, 69,860, 57,317, and 53,170 records, respectively, and are linked to the 2023 MOVEit compromise.
By 2:30 p.m. ET on August 15, Clop had published torrents containing what it claimed were the complete stolen datasets of eight previously named organizations. Its overall victim list stood at roughly 260 organizations, with no newly named victims in that update.
Clop’s publicly named MOVEit victim list had grown to more than 250 organizations by July 28.
A July 5 update reported 36 additional named organizations since the preceding update, with more than 80% doing business in the United States. Clop was generally publishing data about 10 days after naming an organization.
ReliaQuest’s June 26 update reported that Clop had leaked business information belonging to six additional named MOVEit victims.
Clop had named 58 organizations, counting redacted entries, and leaked business data belonging to five companies that day.
Clop added four organizations, resumed leaks from two organizations, and began leaking another organization’s data. The group claimed to possess terabytes of victim data.
Clop released data from two additional organizations and posted a message stating that its objective was money.
Clop claimed to release a third company’s complete stolen dataset at once, rather than publishing it in portions.
By June 20, five organizations had been redacted from Clop’s victim list. Clop claimed that it had deleted all data belonging to the latest organization removed.
Clop added 11 organizations since the preceding update, including its first named Australian organization. It also allegedly leaked a newly named organization’s data at the time of naming it, marking the second reported MOVEit-related leak.
A June 16 afternoon update reported the first possible MOVEit-related data leak. Clop’s site alleged that the named organization had refused negotiations.
By the morning of June 16, Clop had named 37 organizations, including 23 in the United States and its first listed victim from Asia. Financial services, healthcare, and pharmaceutical or biotechnology organizations featured prominently.
Clop’s named victim list reached 27 organizations, including newly listed victims in France, Switzerland, and Luxembourg.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcecyberinsider.com
Open sourceinfostealers.com
Open sourcereliaquest.com
Open sourcereliaquest.com
Open sourcereliaquest.com
Open sourcecoveware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.