• News/
  • https://www.zdnet.com/article/ransomware-attacks-broke-records-in-july-mainly-driven-by-this-one-group/

Ransomware attacks broke records in July, mainly driven by this one group

Charlie Osborne
·
Published Aug 23, 2023
·
Updated

Ransomware attacks reached record levels in July 2023, driven by the Cl0p ransomware group's exploitation of MOVEit software. In a new report released by NCC Group's Global Threat Intelligence team, analysts observed a record number of ransomware-related cyberattacks last month, with 502 major incidents tracked. According to the researchers, this represents a 154% increase year-on-year, compared to 198 attacks traced in July 2022. Also: What is ransomware? Everything you need to know July's numbers represent a 16% rise from the previous month, with 434 ransomware incidents recorded in June 2023. NCC Group says that this record number is due, in no small part, to the activities of Cl0P, a notorious group connected to the exploit of MOVEit software. Cl0p, also known or associated with Lace Tempest, was responsible for 171 of 502 attacks in July, many of which are believed to be down to the exploitation of file transfer software MOVEit. Also: Ransomware has now become a problem for everyone, and not just tech Cl0p has been around since 2019 and is known as a Ransomware-as-a-Service (RaaS) offering to cybercriminals. Also known as -- or associated with -- TA505, Cl0p has aggressively pursued high-value targets with the aim of extorting high ransomware payments, and operators will often steal information prior to encryption in what is known as a double-extortion tactic. If victims refuse to pay up, they risk having their stolen data published online and being named on a public lea...

Read full article

Affected Software

2 affected components
Progress Software MOVEit Transfer
Progress Software MOVEit Cloud
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the record levels of ransomware attacks in July 2023, primarily driven by the Cl0p ransomware group.

2

What security implications are discussed in the article?

The article highlights the significant threats posed by ransomware attacks and their impact on organizations' data security.

3

What group is identified as the main driver of recent ransomware attacks?

The Cl0p ransomware group is identified as the main driver of the surge in ransomware attacks.

4

Which software products are specifically mentioned as being exploited?

The article mentions Progress Software's MOVEit Transfer and MOVEit Cloud as the exploited software products.

5

How did the Cl0p ransomware group achieve their record-breaking attacks?

The group exploited vulnerabilities in the MOVEit software to execute their record-breaking ransomware attacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203