Ransomware

ProPublica / BleepingComputer / DataBreaches.net

πŸ“… 2020-03-13 🦠 CLOP
Primary Source β†—

Incident Details

CLOP ransomware group attacked ExecuPharm, a US clinical research organisation (CRO) and pharmaceutical services company, on March 13 2020. After the company declined to pay, CLOP published stolen files on their leak site β€” one of the earliest high-profile uses of a ransomware leak site. The published data included employee PII: Social Security numbers, financial account information, passport scans, tax documents, and health information for over 150 employees and contractors. The company disclosed the breach on March 27 2020. The incident was notable as an early example of CLOP’s double-extortion model targeting a life-sciences organisation.

Technical Details

Initial Attack Vector
CWE-506: Embedded Malicious Code (CLOP ransomware; initial vector not confirmed)
Malware Family
CLOP

Timeline

  1. 2020-03-13 Breach occurred
  2. 2020-03-27 Publicly disclosed
  3. 2020-03-27 Customers notified