ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Clop ransomware gang exploits GoAnywhere flaw to victimise the City of Toronto

Cyber criminals reportedly exploited a vulnerability in Fortra’s GoAnywhere MFT file transfer application to target The City of Toronto’s networks and systems.In February, security researcher Brian Krebs revealed on Mastodon that GoAnywhere MFT, a popular file transfer application, featured a zero-day vulnerability that enabled remote code injection. Krebs pasted the company’s security advisory that warned existing customers about the bug and the precautionary measures they could take to prevent exploitation.“A Zero-Day Remote Code Injection exploit was identified in GoAnywhere MFT. The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through VPN, or by allow-listed IP addresses (when running in cloud environments, such as Azure or AWS).“If the administrative console is exposed to the public internet, it is highly recommended partnering with our customer support team to put in place appropriate access controls to limit trusted sources,” the advisory read.In a statement shared with the media, the City of Toronto said that on March 20, it became aware of an unauthorised access to stored data.“Today, the City of Toronto has confirmed that unauthorised access to City data did occur through a third party vendor. The access is limited to files that were unable to be processed through the third party secure file transfer system,” the statement read.The City said it has launched an investigation to understand the nature and scope of the cyber attack.“The City of Toronto is committed to protecting the privacy and security of Torontonians whose information is in its care and control and successfully wards off cyber attacks on a daily basis.“The City is still in the early stages of determining the impact of the unauthorized access to City data. If the City’s investigation determines that resident data has been compromised, the City will notify and communicate with any individuals whose information may have been compromised,” a spokesperson said.The Clop ransomware gang, which recently added the City of Toronto to its leak site, has added almost fifty new victims to its leak site in recent months. These organisations include Japanese tech giant Hitachi Energy, Investissement Québec, digital finance giant Hatch Bank, cybersecurity giant Rubrik, luxury brand retailer Saks Fifth Avenue, and many more.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543