Seriously Risky Business Newsletter
October 09, 2025
Clop is a Big Fish, But Not Worth Hunting
Presented by
Policy & Intelligence
The Clop ransomware gang is once again in the news after a mass exploitation campaign targeting users of Oracle's E-business Suite. This month Clop emailed executives at victim companies threatening to leak stolen files if it does not receive payment.
Stealing data to extort companies is not good, but it is a hell of a lot better than systems getting locked up with encrypting ransomware, leading to weeks of factory shutdowns. Right now, from a government perspective, it would be a win if every campaign looked like Clop's.
The group has been active since 2019, making it one of the longer-lasting ransomware gangs. It initially deployed standard encrypting ransomware, but in 2020 it was one of the first groups to experiment with 'double extortion'.