The Clop ransomware group publicly claimed responsibility for breaching The Washington Post, adding the prominent American newspaper to its Tor-based data leak site. The group alleged that the breach resulted from the company's neglect of security responsibilities and threatened to leak stolen data if their demands were not met. Clop's standard tactic involves shaming victims who do not pay by posting accusatory messages and threatening public exposure of sensitive information.
Clop, a Russian-speaking ransomware-as-a-service operation, is known for targeting high-profile organizations using double-extortion methods. The group has a history of exploiting zero-day vulnerabilities in third-party software and leveraging initial-access brokers to infiltrate networks. The Washington Post incident follows a pattern of Clop's attacks on major entities, with the group using its leak site to pressure victims and maximize ransom payments.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Security reporting linked the Oracle EBS attacks to the financially motivated FIN11 group, which is associated with Clop ransomware operations. The suspected campaign involved data theft and extortion rather than only disruptive encryption.
Clop publicly claimed responsibility for breaching The Washington Post and added the newspaper to its Tor-based data leak site, threatening to publish stolen data. The group also criticized the organization over customer security in its posting.
The Oracle EBS attack wave impacted multiple organizations, including The Washington Post, Harvard University, Schneider Electric, Envoy Air, Wits University, and Emerson. The campaign was described as a large-scale intrusion leveraging a widely used enterprise platform to hit numerous victims.
Attackers began exploiting the Oracle E-Business Suite zero-day CVE-2025-61882 in a campaign that security experts said organizations should investigate for signs of compromise dating back to August. The activity enabled long-term access, credential theft, and data exfiltration from affected environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.