Skip to main content
Mallory
Back to intelligence
ransomware-group-operationactively-exploited-vulnerabilitythird-party-vendor-breachunderground-data-leak

Clop-Linked Accellion FTA Exploits Drove Global Data Theft and Extortion

Updated 7d agoFirst seen May 25, 202612 sources

Attackers exploited vulnerabilities in the legacy Accellion File Transfer Appliance (FTA) and deployed a file-downloading web shell to steal data from organizations worldwide, triggering breaches at telecom, legal, financial, and other enterprises. Reporting tied the campaign to the Clop ransomware operation, with additional analysis suggesting overlap with FIN11, as victims including Singtel and a global law firm said their incidents stemmed from compromise at the file-sharing provider rather than direct intrusion into their own networks.

The intrusions were followed by aggressive extortion, including public leak threats and, in at least one case, the exposure of bank employee personal data to pressure payment. Subsequent government warnings said cybersecurity agencies had observed active exploitation of Accellion vulnerabilities, reinforcing the incident as part of Clop’s broader pattern of targeting managed file transfer products to conduct large-scale data theft and shaming-based extortion rather than relying solely on encryption.

Share:
Clop-Linked Accellion FTA Exploits Drove Global Data Theft and Extortion
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Mar 8, 20215y ago

Law firm attributes its data breach to compromise at file-sharing provider

A global law firm later attributed a data breach to the earlier compromise of its file-sharing provider, reflecting the long tail of victim disclosures from the Accellion incident. The statement showed that organizations continued to trace downstream breaches back to the FTA campaign.

Clop leaks bank employee data in Accellion-linked extortion campaign

Clop escalated pressure on victims by publishing personal data of bank employees as part of its extortion efforts tied to Accellion-related breaches. The leak demonstrated the group's willingness to publicly expose stolen information to force payment.

Feb 24, 20215y ago

Cybersecurity agencies issue warning on exploitation of Accellion vulnerabilities

Government cybersecurity agencies published a warning about exploitation of Accellion vulnerabilities, underscoring the broader significance of the campaign and the risks posed by legacy managed file transfer products. The alert placed the Accellion incidents in the context of recurring exploitation activity against file transfer software.

Feb 23, 20215y ago

Mandiant assesses FIN11 likely behind Accellion FTA intrusions

Mandiant said Accellion FTA attacks and related extortion activity were likely the work of FIN11, a financially motivated group associated with Clop operations. The assessment refined attribution by linking the exploitation to a specific threat actor cluster.

Feb 22, 20215y ago

Researchers link Accellion breach extortion to Clop ransomware gang

Reporting tied the wave of Accellion-related data theft and extortion incidents affecting multiple organizations to the Clop ransomware operation. This marked a major attribution development connecting the campaign to a known cybercriminal group.

Feb 9, 20215y ago

Singtel says a third-party Accellion FTA breach exposed customer data

Singapore telecommunications provider Singtel disclosed that a breach of its third-party file-sharing system, Accellion FTA, affected customer information. The incident highlighted that downstream organizations using the platform were suffering data exposure.

Jan 28, 20215y ago

Researchers report a file-downloading web shell used in Accellion FTA attacks

GuidePoint Security described a targeted campaign against Accellion FTA in which attackers deployed a web shell used to download files from compromised appliances. The reporting added technical detail on how the intrusions were being carried out.

Jan 25, 20215y ago

Accellion identifies additional FTA vulnerabilities and issues more fixes

After the initial disclosure, Accellion found additional vulnerabilities affecting FTA and released further patches in late December 2020 and January 2021. The expanding scope showed attackers were chaining multiple flaws against the appliance.

Dec 20, 20205y ago

Accellion discloses FTA zero-day attacks and releases initial patch

Accellion disclosed that its legacy File Transfer Appliance (FTA) was being targeted in zero-day attacks and issued an initial patch for affected customers. The incidents involved exploitation of the end-of-life file transfer product to gain unauthorized access to stored files.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Clop-Linked Accellion FTA Exploits Drove Global Data Theft and Extortion | Mallory