The CL0P ransomware operation has added motorcycle manufacturer Harley-Davidson to its public extortion leak site, claiming it compromised the company. The listing was highlighted by the ransomNews threat-monitoring account, but Harley-Davidson and its parent organization have not publicly confirmed an intrusion or data theft.
CL0P provided no sample files, screenshots, ransom note, stolen-data archive, or technical indicators to substantiate the claim. The purported initial-access vector, affected business unit, scope and type of data allegedly stolen, and whether ransomware encryption occurred remain unknown; the incident should be treated as unconfirmed pending independent validation or an official disclosure.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
The CL0P ransomware operation allegedly added Harley-Davidson to its public extortion leak site and claimed it had compromised the motorcycle manufacturer. The ransomNews threat-monitoring account highlighted the unverified listing; no supporting evidence accompanied the claim, and Harley-Davidson had not publicly confirmed an intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.