
The infamous Clop ransomware gang targeted the City of Tasmania in Australia by exploiting a zero-day vulnerability in Fortra’s GoAnywhere MFT file transfer application.In February, security researcher Brian Krebs revealed on Mastodon that GoAnywhere MFT, a popular file transfer application, featured a zero-day vulnerability that enabled remote code injection. Krebs pasted the company’s security advisory that warned existing customers about the bug and the precautionary measures they could take to prevent exploitation.“A Zero-Day Remote Code Injection exploit was identified in GoAnywhere MFT. The attack vector of this exploit requires access to the administrative console of the application, which in most cases is accessible only from within a private company network, through VPN, or by allow-listed IP addresses (when running in cloud environments, such as Azure or AWS).“If the administrative console is exposed to the public internet, it is highly recommended partnering with our customer support team to put in place appropriate access controls to limit trusted sources,” the advisory read.The Clop ransomware group exploited the zero-day vulnerability to the hilt, compromising at least 130 organisations worldwide. According to security researcher Dominic Alvieri, the gang has listed “56 victims within 24 hours.” These organisations include Japanese tech giant Hitachi Energy, Investissement Québec, digital finance giant Hatch Bank, cybersecurity giant Rubrik, luxury brand retailer Saks Fifth Avenue, and many more.Last Friday, the ransomware group added the City of Tasmania to its data leak site along with several other companies and municipalities.In a statement shared with news agencies, a spokesperson from Tasmania’s Department of Premier & Cabinet, said that “the Government is aware of these reports and they are being investigated.”The ransomware group last week added the City of Toronto to its leak site as well. After the news came to light, the City of Toronto said that on March 20, it became aware of unauthorised access to stored data. The City said it has launched an investigation to understand the nature and scope of the cyber attack.According to Louise Ferrett, Threat Intelligence Analyst at Searchlight Cyber, this isn’t the first time Cl0p has ‘mass-hacked’ a number of organisations by exploiting vulnerabilities in third-party software. In late 2020 - early 2021 it used the same tactic to attack more than 100 organizations with Accellion’s legacy File Transfer Appliance, using a combination of zero-day vulnerabilities and a new web shell.“This time the operation has used CVE-2023-0669 in Fortra’s GoAnywhere MFT secure file transfer tool. This approach of targeting multiple organisations and then announcing them in quick succession distinguishes Cl0p from other ransomware operations.“Cl0p is a ransomware-as-a-service operation, which means that a number of affiliates use its ransomware in their attacks. It is noteworthy for having links to larger cybercriminal gangs such as FIN11 and TA505, for often targeting high-profile organisations, and for its longevity (in dark web terms), having emerged in February 2019 as a variant of the CryptoMix ransomware strain,” she added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543