
The Clop ransomware gang has claimed to have attacked prominent luxury brand retailer Saks Fifth Avenue on its dark web leak site as part of its ongoing attacks against vulnerable GoAnywhere MFT servers belonging to established enterprises.
The gang has listed Saks Fifth Avenue among its latest victims on its data leak website. The threat actor has not disclosed any additional information, whether it stole customer data from the retailer’s systems or details about ongoing ransom negotiations.
While the retailer stated that no "real" customer or payment data was stolen, it did not answer whether employee or corporate data was compromised in this incident. In collaboration with outside experts and law enforcement, the company conducts an ongoing investigation into this incident.
Meanwhile, the reports have confirmed that the cyber security incident was linked to the previously reported zero-day vulnerability in file transfer (MFT) software, GoAnywhere. A Saks spokesperson also confirmed the incident was linked to GoAnywhere.
The security flaw, currently tracked as CVE-2023-0669, allows attackers to obtain remote code execution on unpatched GoAnywhere MFT instances with their administrative console exposed to the Internet. Clop claimed to have breached 130+ organizations in ten days, including Hitachi Energy and Rubrik, exploiting this vulnerability on enterprise servers.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543