Cl0p had been quiet for a month. On 12 August the extortion crew posted 45 organizations to its data-leak site in a single batch, and the domains it named include ge.com, shell.com, philips.com, fiserv.com and aol.com.
The tempo is the story here, not the total. IntelFusions logs leak-site claims as trackers surface them, and in the 30 days before that batch Cl0p accounted for three claims in our data: one on 31 July and two on 7 August. Then 44 landed inside a single collection window on 12 August, with a 45th following the next day. A crew averaging well under one victim a week named 45 in an afternoon.
None of this is confirmed. These are claims the extortionists published about themselves, on an onion site we do not link, and the listings carry no evidence of what was taken, when it was taken, or whether the organization named is the one that was actually breached. Most entries are bare domains rather than company names, which is Cl0p's habit, and it makes a parent company hard to tell apart from a subsidiary or a supplier.
Household names sitting beside small suppliers
Nineteen of the 45 listings are US domains. The rest spread across 17 other countries, from Canada and Switzerland to Taiwan, Kazakhstan and Peru, with one entry we could not place at all. Country is inferred from the domain here and is occasionally wrong.
The recognizable names are what stand out. Alongside ge.com, shell.com, philips.com, fiserv.com and aol.com, the list carries the payment platforms toasttab.com and clover.com, the footwear group aldogroup.com, the outdoor brands mammut.com, Suunto and lifestraw.com, the hearing-aid maker starkey.com, the flask maker thermos.com, the British nursery retailer mamasandpapas.com, and Taiwan's Largan Precision, which supplies camera lenses to the world's phone makers. Sitting between them are engineering shops, regional IT firms and a US university research center.
A batch drop is Cl0p's signature, but the cause is not stated
Cl0p's pattern for years has been to exploit one widely deployed product at scale, take data from everyone running it, then publish the victims in waves rather than one at a time. CISA and the FBI described that shape in their 2023 advisory on the crew's MOVEit campaign, and our own profile of the group records the same behaviour around GoAnywhere. A batch of 45 in a day fits the pattern exactly.
What the pattern does not give us is the way in. Cl0p named no product and no flaw in these listings, and IntelFusions has seen no vendor advisory connecting them. The honest position is that the shape of the drop is familiar and its cause is unknown. Anyone stating otherwise this week is guessing.
Treat a listing as a lead, not a verdict
If your organization or one of your suppliers appears, treat it as something to check rather than something that happened. Preserve authentication and file-transfer logs before they roll over, look for bulk downloads from internet-facing systems in the weeks before 12 August, and ask any third party holding your data whether it has something to disclose. A leak-site entry is not proof of compromise, and its absence is not proof of the opposite: crews publish selectively and hold names back as leverage.
Single-day floods are not unique to this crew. Deadlock posted 65 victims in one day in July, and claims against Indian firms tripled in a month with no single group driving it. What separates this batch is who is in it. Extortion lists usually read as mid-market companies nobody outside their sector could name. This one reads like a page torn out of a multinational's supplier directory.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.