Attackers exploited vulnerabilities in the legacy Accellion File Transfer Appliance (FTA) and deployed a file-downloading web shell to steal data from organizations worldwide, triggering breaches at telecom, legal, financial, and other enterprises. Reporting tied the campaign to the Clop ransomware operation, with additional analysis suggesting overlap with FIN11, as victims including Singtel and a global law firm said their incidents stemmed from compromise at the file-sharing provider rather than direct intrusion into their own networks.
The intrusions were followed by aggressive extortion, including public leak threats and, in at least one case, the exposure of bank employee personal data to pressure payment. Subsequent government warnings said cybersecurity agencies had observed active exploitation of Accellion vulnerabilities, reinforcing the incident as part of Clop’s broader pattern of targeting managed file transfer products to conduct large-scale data theft and shaming-based extortion rather than relying solely on encryption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
A global law firm later attributed a data breach to the earlier compromise of its file-sharing provider, reflecting the long tail of victim disclosures from the Accellion incident. The statement showed that organizations continued to trace downstream breaches back to the FTA campaign.
Clop escalated pressure on victims by publishing personal data of bank employees as part of its extortion efforts tied to Accellion-related breaches. The leak demonstrated the group's willingness to publicly expose stolen information to force payment.
Government cybersecurity agencies published a warning about exploitation of Accellion vulnerabilities, underscoring the broader significance of the campaign and the risks posed by legacy managed file transfer products. The alert placed the Accellion incidents in the context of recurring exploitation activity against file transfer software.
Mandiant said Accellion FTA attacks and related extortion activity were likely the work of FIN11, a financially motivated group associated with Clop operations. The assessment refined attribution by linking the exploitation to a specific threat actor cluster.
Reporting tied the wave of Accellion-related data theft and extortion incidents affecting multiple organizations to the Clop ransomware operation. This marked a major attribution development connecting the campaign to a known cybercriminal group.
Singapore telecommunications provider Singtel disclosed that a breach of its third-party file-sharing system, Accellion FTA, affected customer information. The incident highlighted that downstream organizations using the platform were suffering data exposure.
GuidePoint Security described a targeted campaign against Accellion FTA in which attackers deployed a web shell used to download files from compromised appliances. The reporting added technical detail on how the intrusions were being carried out.
After the initial disclosure, Accellion found additional vulnerabilities affecting FTA and released further patches in late December 2020 and January 2021. The expanding scope showed attackers were chaining multiple flaws against the appliance.
Accellion disclosed that its legacy File Transfer Appliance (FTA) was being targeted in zero-day attacks and issued an initial patch for affected customers. The incidents involved exploitation of the end-of-life file transfer product to gain unauthorized access to stored files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcebleepingcomputer.com
Open sourcecshub.com
Open sourcerisky.biz
Open sourceguidepointsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.