
The infamous Clop ransomware gang has named ten new organisations that it victimised by exploiting a zero-day vulnerability in the MOVEit Transfer file transfer application.On Monday, the Clop ransomware gang listed about ten new organisations to its list of victims. One of the organisations targeted by the group is TJX Companies, the parent company of popular retail brands like TJ Maxx.While little is known about negotiations between the company and the ransomware group, a TJX Companies spokesperson said, “TJX is among a number of companies impacted by a widespread global cybersecurity event related to a vulnerability in Progress Software’s file transfer software MOVEit Transfer.“Although we are aware some files were downloaded by an unauthorised third party before Progress notified us of the vulnerability, based on current information, we do not believe there was any unauthorized access to any customer or Associate personal information on TJX’s systems or any material impact to TJX.“We take protecting the data of our customers, Associates, and vendors seriously and we continue to monitor the situation closely.”Another industry giant listed by the Clop ransomware group as a victim of the global cyber security incident is TomTom, a Dutch multinational developer and creator of location technology and consumer electronics.TomTom provides satellite navigation platforms to several industry pioneers including Uber, Verizon, Microsoft, and major automotive manufacturers like Maserati, BMW, Renault, Volkswagon, Toyota, Mazda, and more. The ransomware group has claimed to have gained access to more than 82GB of data stolen from the company.Acknowledging the group’s claims, a TomTom spokesperson said, “We at TomTom were immediately aware of a data breach that occurred on our vendor’s platform, MOVEit, last month. We have taken all necessary safety and security measures to protect any data, and we have informed the relevant authorities.”The other organisations listed by the Clop ransomware group as victims of the MOVEit Transfer hack were Compucom, Canada’s Sierra Wireless, US company RCI, Germany’s Vitesco Technologies, Australian company Fortescue, and Danish pump-maker DESMI.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543