Seven European logistics operators confirmed affected. Customs declarations, shipment manifests, commercial invoice data: exfiltrated before most victims knew the campaign was running. Cl0p doesn’t give the sector time to react; that’s the whole point.
This is the fourth major MFT exploitation campaign from this group in five years. MOVEit Transfer in 2023. GoAnywhere MFT in 2023. Accellion in 2021. Now this. The playbook is unchanged: find a critical vulnerability in a platform woven into supply chain operations, exploit it at mass scale before patches land, pull data from hundreds of organisations simultaneously, then monetise through ransom demands or leak site publication.
Cl0p is effective at this because the approach doesn’t require sustained access. Hit the platform, pull the data, move on. The exploitation window is days. Victims are still assessing their exposure when the ransom note arrives.
Why this sector keeps ending up in the crosshairs
Transport and logistics depends on automated file transfer. Ports, customs authorities, freight forwarders, third-party logistics providers: they’re all exchanging documents through these platforms continuously. The architecture is almost always direct internet-facing access, minimal additional controls, and a small IT team managing a platform that can’t go down without disrupting active shipments.
The sector’s operational continuity pressure is the security vulnerability. Patching an MFT platform mid-operation means risk of disruption to live customs filings and freight documentation. So patches slip. Firmware versions age. The platforms stay internet-reachable. And Cl0p waits for the next disclosed vulnerability in exactly this class of software.
What was taken and why it matters
The exfiltrated data has several distinct value propositions, not all of them obvious.
Customs and import/export documentation reveals trade relationships, supplier networks, and product volumes: valuable to competitors, to state actors monitoring sanctions compliance, and to criminal networks planning cargo theft. Shipment tracking data narrows those interests to specific movements in real time. Commercial agreements and pricing have direct competitive intelligence value. Employee and customer personal data triggers ICO notification obligations: 72 hours from discovery, not from when you’ve confirmed exfiltration.
That last point matters. If your MFT platform was running and internet-facing during this campaign window, you’re likely in scope for a notification assessment even before you’ve confirmed what was taken.
What to do now
Find every MFT platform your organisation uses, including the ones third-party logistics providers are running on your behalf and exchanging your data through. That scope is larger than most organisations initially assume.
Apply the available patch. Cl0p’s operational model compresses the window between disclosure and mass exploitation to days. The campaign has been running; every day of delay is exposure that’s likely already been converted into exfiltrated data for some victims.
Pull audit logs from your file transfer platform for the past 30 days and look for anomalous bulk download activity. The forensic signal is usually there.
Contact your data protection officer and run the ICO notification assessment. Then talk to your key logistics partners: if your MFT was compromised, their data was likely in it too.
NCSC can brief qualifying organisations on the specific CVE and affected platform versions through its partnership programmes while broader patch deployment is still in progress. If you’re in the sector and not already in contact with NCSC, this is a reasonable moment to establish that.