The Clop ransomware group has created the MOVEit exploit using a zero-day vulnerability in third-party file transfer software MOVEit Transfer, owned by Progress Software. The aim of the attack was data theft, particularly personally identifiable information (PII) from customer databases.
The vulnerability, now tracked as CVE-2023-34362, is believed to have been exploited since around May 27th and has led to multiple waves of data breaches in the weeks following. Shortly after attacks began, Progress identified the vulnerability and a patch was offered in late May, though not all clients applied it. Since then, advisories on other vulnerabilities have been issued with fixes closely following.
The ransomware group gave impacted companies until June 14th to contact them. On that deadline day, the names of 13 companies was released on their leak site. In the days that have followed, numerous other companies have been named. The group has stated that it will start publishing content from those organizations that do not negotiate an extortion payment by June 21st.
Clop have recently released a statement claiming that it has erased all data stolen from government, city, and police services as they have “no interest to expose such information.”
It has emerged that Clop ransomware gang has started to create clearweb sites to leak stolen stolen during these recent MOVEit Transfer data theft attacks. The first site was created by threat actors for PwC, where all leaked company data was posted in four spanned ZIP archives. Websites have also been created for Aon, EY, Kirkland and TD Ameritrade.
The current victim list is massive and growing, and Clop continues to share new entries every day, which begs the question, how many companies have actually been affected by this attack? Some victims have publicly announced their involvement in the breach, other have simply been named by Clop themselves. We’ll be following this attack closely and updating this blog with new information as the story unfolds.
Let’s take a look at the victims that have been announced to date:
- 1871, German life insurance provider (impacted by Majorel)
- 1st Source Bank, Michigan based bank
- A + Federal Credit Union, Texas based Credit Union
- AbbVie, US based pharmaceutical company.
- Abilene Christian University in Texas (impacted by NSC)
- Accelya Global Ltd, European IT services provider (impacted by Alight)
- Aclara, US based software company
- Adare SEC, UK based advertising services provider
- Advanced Integration Technology, Texas based aviation component manufacturer
- Aerlingus, Irish airline (impacted by Zellis)
- Aetna Life Insurance Company (impacted by PBI)
- Agilysys, US based software developer
- Aging Services Access Points (ASAP), based in Massachusetts
- Alfa Laval, Swedish manufacturing company
- Alfred State College in New York (impact by NSC, TIAA and Corebridge)
- Allegheny County in Pennsylvania
- Allegiant Air, US based airline
- Allegis Group, management company based in Maryland (impacted by Sovos)
- Allison Transmission, manufacturer based in US
- Alogent, US based banking software company
- Aloha Pacific Federal Credit Union in Hawaii
- AlohaCare, Hawaii based not for profit health plan providers
- AltaMed Health Services, based in California (indirectly impacted by Vitality and TIAA/PBI)
- AMC Theatres, Kansas based entertainment organization
- American Airlines
- American Board of Internal Medicine
- American Civil Liberties Union Foundation
- American General Life Insurance Company
- American National Insurance
- Ameriprise Financial, based in Minnesota
- Amerisave, US based mortgage providers
- AmeriServ Financial Bank, based in Pennsylvania
- AOK, an association of statutory health insurers based in Germany. Insurers impacted include AOK Baden-Württemberg, AOK Bayern, AOK Bremen/Bremerhaven, AOK Hessen, AOK Niedersachsen, AOK Plus, AOK Rheinland-Pfalz/Saarland, AOK Sachsen-Anhalt
- Aon, global insurance company
- Appriss, US based software company (impacted by Vitality)
- ARBURG, European plastics manufacturer
- Arietis Health, US based medical billing service
- Aristocrat, global gaming and technology company
- Arizona State University (impacted by NSC, TIAA and United Healthcare)
- Arkansas Tech University (impacted by NSC and TIAA)
- Arvato, global services company based in Germany
- Asheville-Buncombe Technical Community College (impacted by NSC)
- AspenTech, US based software company
- Athene Annuity and Life Company, based in Iowa
- Aurora Life Insurance, based in Texas (impacted by Alliance-One)
- Ausburg University in Minnestoa (impacted by TIAA)
- Austrian Finance Market Authority
- Autozone, US based retailer
- Baesman, US based marketing services provider
- Baird Insurance Services in Milwaukee (impacted by PBI)
- Baker College in Michigan (impacted by NSC)
- Baltimore County in Maryland (impacted by PBI)
- Banco Agromercantil de Guatemala
- Banco Popular de Puerto Rico (impacted by PwC)
- Bank of America, impacted by breach on EY
- Bank of Burlington, impacted by Darling Consulting)
- Bank of Montgomery, based in Louisiana
- Bank of Nova Scotia
- Bank OZK, based in Arkansas
- Bank99, Austrian bank
- BankGloucester in Massachusetts (impacted by Darling Consulting)
- BankNewport, based in Rhode Island (impacted by Darling Consulting)
- Bar Harbor Bank, US based bank
- Barmer, Berlin based health insurance company.
- Barrett Business Services Inc, management consultancy company based in Washington (impacted by Sovos)
- Barrick Gold, Canadian mining company
- Barton Community College in Kansas (impacted by NSC)
- Bates Technical College in Washington (impacted by NSC)
- Bayern Versicherung Lebensversicherung, German life insurance providers (impacted by Majorel)
- BBC, broadcasting company based in UK (impacted by Zellis)
- BCD Travel, US based travel management company
- Bellevue College in Washington (impacted by NSC and TIAA)
- Beneva, Quebec-based insurance company
- Bennett College in North Carolina (impacted by NSC)
- BioMerieux, French biotechnology company (impacted by Vitality)
- Bismark State College in North Dakota (impacted by NSC)
- Blackhawk Technical College in Wisconsin (impacted by NSC)
- BlueCross BlueShield of Illinois (impacted by TMG Health)
- Bluefin, US bases financial services provider
- Blue Shield of California
- Boise State College in Idaho (impacted by NSC and TIAA)
- BOM Bank in Louisiana (impacted by First National Bankers Bankshares)
- Boots, British beauty retailer (impacted by Zellis)
- BORN Ontario, healthcare organization in Canada
- Boston Globe, US daily newspaper
- Boston University (impacted by TIAA and NSC)
- Brady, US based safety, compliance and identification organization
- Brault, US based technology firm
- Brighthouse Life Insurance Company
- Bristol Myers Squibb, US based pharmaceutical company
- British Airways, airline based in the UK (impacted by Zellis)
- Brookfield, Canadian multinational investment management company
- Buffalo State University in New York (impacted by NSC, TIAA and Corebridge)
- Butler Community College (impacted by NSC)
- C & F Insurance, US based insurance provider
- Cadence Bank, US based bank
- California Public Employees’ Retirement System (impacted by PBI)
- California State Teachers Retirement System (impacted by PBI)
- Cambridge Trust Company based in Massachusetts
- Cambridgeshire City Council based in UK
- Capital Small Finance Bank in India (impacted by Kotak Mahindra Life Insurance)
- Capitol Federal (CapFed) in Kansas (impacted by FIS)
- Care N’ Care Insurance Company in Texas (impacted by TMG Health)
- CareServices LLC, US based healthcare services provider
- CareSource, Ohio based not for profit organization
- Carl Albert State College in Oklahoma (impacted by NSC)
- CBE, construction company based in Australia
- CBIZ, accounting services in Missouri
- CCED, oil and gas company based in Oman
- CCleaner, file cleansing software
- Cedarville University in Ohio (impacted by TIAA)
- Cegedim SA, French technology company
- Chadron State College in Nebraska (impacted by NSC)
- Chapman University in California (impacted by NSC and TIAA)
- CHEO, based in Ottawa (impacted by BORN Ontario)
- Chesapeake College in Maryland (impacted by TIAA and NSC)
- Chevron Federal Credit Union based in California
- China CITIC Bank, commercial banking company
- Chuck E Cheese, US family entertainment chain
- CIBC Private Wealth Management (impacted by PBI)
- Ciena, US telecommunications company
- City National Bank of Florida
- CLEAResult, Texas based utilities company
- Clearwater Credit Union (impacted by Alogent)
- Clemson University in South Carolina (impacted by TIAA and Corebridge)
- Cleveland State Community College in Ohio (impacted by NSC)
- Clicks Group, South Africa based health retailer.
- Club Vita US, financial services provider (impacted by PBI)
- CMFG Life Insurance Company, based in Wisconsin
- Cognizant, multinational IT services and consulting company
- College of American Pathologists
- College of Southern Idaho (impacted by NSC and TIAA)
- College of Western Idaho (impacted by NSC and TIAA)
- Collin College in Texas (impacted by NSC breach)
- Colorado Department of Health Care Policy and Financing
- Colorado School of Mines (impacted by NSC)
- Colorado State University (impacted by NSC, TIAA, Corebridge, Genworth, Sunlife and the Hartford)
- Colorado State University System (impacted by NSC and PBI)
- Comdirect in Germany (impacted by Majorel)
- Community College of Baltimore County (impacted by NSC and TIAA)
- Community Trust Bancorp Inc (CTBI), based in Kentucky
- CompuCom, US based IT services provider
- ComReg, Irish general communications regulator
- Concordia Plans, financial services provider based in Missouri (impacted by Vitality and PBI)
- Conseil scolaire acadien provincial (CSAP), school board in Nova Scotia
- CONSOL Energy, US based energy company
- Consolidated Edison Company of New York (impacted by PBI)
- Continental Automotive Systems Inc, automotive parts manufacturer
- Continental General Insurance Company in Texas (impacted by MassMutual)
- ConvergeOne, US based IT services provider
- Corebridge Financial, US based financial services provider
- Corewell Health based in US (impacted by Welltok)
- County of Santa Clara, California (impacted by PBI)
- CPIAI, Texas based insurance company
- Cree Lighting, US-based LED lighting manufacturer
- Criswell College in Texas (impacted by NSC)
- Crowe, US based accountancy and advisory firm
- CU*Answers, US based software company
- Curry College in Massachusetts (impacted by NSC)
- CWT, US based travel management company
- Cytomx Therapeutics, US based biopharmaceutical company
- Dakota College in North Dakota (impacted by NSC)
- Darling Consulting Group, US based financial advisor
- Data Media Associates, technology company based in US
- Datasite LLC, US based SaaS provider
- De Anza College in Santa Clara (impacted by NSC)
- De La Rue, printing company based in UK
- Delaware Life, US based insurance company
- Deloitte, multinational professional services provider
- Delta Dental of Iowa (impacted by Sovos)
- DESMI, industrial machinery manufacturer based in Denmark
- Deutsche Bank in Germany (impacted by Majorel)
- DHL, German logistics company
- Dickinson State University in North Dakota (impacted by NSC)
- Digital Insight, US based software provider.
- Disability Reinsurance Management Services, based in Maine
- Discovery, US based media organization
- District of Columbia Department of Health Care Finance (impacted by Maximus)
- Dow Credit Union in Michigan
- Drake University in Iowa (impacted by NSC and TIAA)
- Druckerei Kyburz, printing company in Switzerland
- Durr, global mechanical and plant engineering firm.
- East West Bank, US based bank
- Eastern Washington University (impacted by NSC and TIAA)
- EBS Services, insurance provider based in Alabama (impacted by PBI)
- Edmonds College in Washington (impacted by NSC and TIAA)
- Elmwood Family Health Centre (impacted by BORN Ontario)
- Elips Life Insurance Company
- Emerson, multinational manufacturing company
- Empire State University in New York (impacted by NSC, TIAA, CREF and Corebridge)
- Employees Retirement System of Rhode Island (impacted by TIAA)
- EMS Management and Consultants, medical billing service based in North Carolina. This breach impacted at least 16 counties across the US.
- EMSS Inc, Hawaii based IT services and IT consulting organization
- Encore Capital Group, US based financial services company
- Encova Mutual Insurance Group in Ohio (impacted by UnitedBank)
- Energy Transfer, US based energy company
- Enstar Group, insurance company based in Bermuda
- Enterprise Bancorp, US commercial banking company
- Envision Financial Systems, US based software development company
- Ernst & Young (EY), global accountancy firm
- Everett Community College in Washington (impacted by NSC and TIAA)
- Eversource, Boston based utility company (impacted by CLEAResult)
- Executive Office of Health and Human Services (EOHHS) in Massachusetts (impacted by UMass Chan)
- Extreme Networks, US based software development company
- F&G Annuities & Life, US based financial company
- FANUC America, robotics company
- Farmingdale State College in New York (impacted by TIAA, NSC and Corebridge)
- Feather River College in California (impacted by NSC)
- Ferring Pharmaceuticals, Swiss pharmaceutical company
- Fiduciary Outsourcing, US based fiduciary retirement plan administration provider
- Financial Institution Service Corporation, US based consultancy firm
- First Commonwealth Bank, based in US
- First Farmers Bank & Trust, based in Indiana
- First Fed Bank based in Washington (impacted by Darling Consulting)
- First Merchants Bank, financial service providers based in Indiana
- First National Bank of Omaha (FNBO), based in Nebraska
- First National Bankers Bank, US based bank services provider
- FirstSun Capital Bancorp in Denver, Colorado
- FIS Global, multinational financial services organization
- Fiserv, multinational financial technology provider
- Flagstar Bank, based in Michigan (impacted by Fiserv)
- Florida Healthy Kids Corporation (impacted by Maximus)
- Flutter, British sports betting company (impacted by Maximus)
- Foothill College in California (impacted by NSC)
- Foresters Financial, insurance company based in Canada
- Fortescue, Australian iron ore company
- Franklin Mint Federal Credit Union, based in Pennsylvania
- Fredonia State University of New York (impacted by NSC, TIAA and Corebridge)
- FullScopeRMS, US based insurance provider (impacted by PBI)
- Gannon University in Pennsylvania (impacted by NSC)
- Garden City Community College in Kansas (impacted by NSC and TIAA)
- Garrett Motion, Swiss manufacturing company
- GEICO, Texas based insurance company
- Gen Digital, the parent company of cybersecurity brands Avast, Avira, Norton and LifeLock
- Genericon Pharma, Pharmaceutical company based in Austria
- Genesis Energy LP based in Texas
- Gensler, US based architecture firm
- Genworth Financial, US based insurance company
- Gesa, Washington based Credit Union
- Glacier Bancorp, based in Montana (impacted by Darling Consulting)
- Global Atlantic Financial Group based in the US (impacted by PBI)
- Goal Structured Solutions, finance firm based in US
- Government of Illinois
- Government of Nova Scotia including Dept of Justice, Dept of Education, Dept of Labor, Skills and Immigration, Election Authority, Dept of Health and Wellness, Dept of Communities, Culture and Tourism and Nova Scotia Health Authority.
- Governors State University in Illinois (impacted by NSC and TIAA)
- Grace, US based chemical manufacturer
- Grand View University in Iowa (impacted by NSC)
- Greater Rochester Independent Practice Association, US based healthcare provider
- Green River College in Washington (impacted by NSC)
- GreenShield Canada, a non-profit benefits carrier
- GreenSky, financial technology company in Georgia (impacted by Sovos)
- Grossmont-Cuyamaca Community College District in California (impacted by NSC )
- Groves Memorial Community Hospital (impacted by BORN Ontario)
- Guelph General Hospital (impacted by BORN Ontario)
- Guidepoint Security, IT service provider based in Virginia (impacted by Vitality)
- GUS Canada, a network of higher education institutions in Canada.
- Halifax Regional Municipality
- Halma, UK based technology company
- Hamilton College in New York (impacted by NSC and TIAA)
- Hamilton Health Services (impacted by BORN Ontario)
- Harris Health System based in Texas
- Hartford Life & Accident Company
- Health Sciences North Horizon Santé-Nord (impacted by BORN Ontario)
- HealthEquity, US based financial technology and business services provider
- Heidelberger Druckmaschinen, German precision engineering company
- Helen Fuld College of Nursing in New York (impacted by NSC)
- Herkimer College in New York (impacted by NSC, TIAA and Corebridge)
- Hero FinCorp, consumer bank company in India (impacted by Kotak Mahindra Life Insurance)
- Hess, global independent energy company
- Highmark Blue Cross Blue Shield, based in Delaware
- Hillsborough County in Florida
- Hinduja Group, Indian transnational conglomerate
- Honeywell, US based multinational conglomerate corporation
- Horizon Bank, based in Indiana
- Hornbeck Offshore, US based maritime transport company
- Hospices Civils de Lyon, French hospital
- HSE, public health service in Ireland
- Humana, American health insurance company
- Huntington National Bank in Ohio (impacted by Alogent and Baesman)
- IC System, US based debt collection services
- Idaho State University (impacted by NSC and TIAA)
- Illinois Department of Innovation and Technology
- Illumifin Corporation, based in South Carolina
- Independence Community College in Kansas (impacted by NSC)
- Indiana Family and Social Services Administration (impacted by Maximus)
- Indiana State University (impacted by TIAA, PBI and NSC)
- Indiana University (impacted by TIAA and NSC)
- Informatica, US based software company
- ING, banking service provider in Germany (impacted by Majorel)
- Iron Bow Technologies, software company based in Virginia
- IS Digitoday, Finnish technology company
- ISCorp, software company based in Wisconsin
- ITT Inc, US based manufacturing company
- IU Health Plans based in Indiana
- IWK Health Centre, based in Halifax, Nova Scotia.
- Jack Entertainment, Ohio based entertainment company
- Jackson National, life insurance company based in Colorado
- Jackson State Community College in Tennessee (impacted by NSC)
- Japan Tobacco International (JTI), global tobacco company based in Japan
- John A Logan College in Illinois (impacted by NSC)
- John Hopkins Advantage MD
- John Hopkins All Children’s Hospital
- John Hopkins University and Health System, based in Baltimore, Maryland
- Jonas Fitness, US based fitness software company
- Jones Lang LaSalle Human Resources, based in Chicago
- JP Recovery Services, debt collection services
- K&L Gates, US based law firm.
- Kale Aero, aerospace company based in Turkey
- Kale Pratt & Whitney Business School, based in Turkey
- Kansas City Kansas Community College (impacted by NSC)
- Kansas City Life Insurance Company (impacted by FullscopeRMS)
- Kearny Bank (impacted by Fiserv)
- Kennedy Krieger Institute in Maryland
- Kentucky Community & Technical College System (impacted by NSC and TIAA)
- KERN Agency, US based advertising services
- KIPP Public Schools in California (impacted by Paycom)
- Kirkland & Ellis, multinational law firm.
- Kotak Life, life insurance company based in India
- Kuecker Logistics Group, US based logistics management company
- Lake Forest College in Illinois (impacted by NSC, United Healthcare and TIAA)
- Lake Sumter State College in Florida (impacted by NSC)
- Landal Greenparks, European holiday facilities
- Lansing Community College in Michigan (impacted by NSC and TIAA)
- Leader Bank based in Massachusetts
- Leech Lake Tribal College in Minnesota (impacted by NSC)
- Leggett and Platt, US based manufacturing firm
- Lehigh University in Pennsylvania (impacted by TIAA)
- Level 8 Solutions, UK based IT consultancy firm
- Lewis-Clark State College in Idaho (impacted by NSC)
- Lincoln College in Missouri (impacted by NSC)
- Lincoln Savings Bank based in Iowa (impacted by Darling Consulting)
- Lombard International Life Assurance Company
- London Health Sciences Centre (impacted by BORN Ontario)
- Louisiana’s Office of Motor Vehicles (OMV)
- Loyal American Life Insurance Company based in Tennessee (impacted by PBI)
- Loyola University Chicago (impacted by NSC and TIAA
- Lumico Life Insurance Company based in New York (impacted by NTT Services)
- Lycoming College in Pennsylvania (impacted by NSC and TIAA data)
- M&T Bank Corporation, based in New York
- MACOM, US based semiconductor manufacturers
- Madison College in Wisconsin (impacted by NSC)
- Majorel, international service company.
- Manhattan National Life Insurance Company
- Marshall University in West Virginia (impacted by NSC and TIAA)
- Marti Group, Swiss contracting company
- Mary Kay Cosmetics
- Maryland Department of Human Services
- Maryland State Retirement and Pension Scheme (impacted by TIAA)
- Mascoma Bank in New Hampshire
- Massachusetts College of Pharmacy and Health Sciences (impacted by NSC)
- MassMutual, based in Massachusetts
- Mauch Chunk Trust Company, financial services provider in Pennsylvania (impacted by Darling Consultancy)
- Maximus, US government contractor
- Mechanics Bank, California based community banking services
- Medibank Private Ltd, Australian health insurance providers
- Medical College of Wisconsin
- Members Life Insurance Company, based in Wisconsin
- Merative, American medical technology company
- MESVision, California based eye care provider
- Metro Vancouver Transit Police
- Michigan State University (impacted by NSC and TIAA)
- Middlebury College in Vermont (impacted by NSC and TIAA)
- MidFirst Bank in Oklahoma
- Midland States Bank based in Illinois (impacted by Sovos)
- Milliman Solutions, US based business consulting service provider. This breach reportedly impacted 219 organizations across the US.
- Minnesota Department of Education
- Mississippi Gulf Coast Community College (impacted by NSC)
- Missouri Department of Social Services (DSS)
- Montcalm Community College in Michigan (impacted by NSC)
- Montclair State University in New Jersey (impacted by NSC and TIAA)
- Monterey Peninsula College in California (impacted by NSC)
- Motherson, Indian automotive component manufacturer
- MS Amlin, UK based insurance operator
- NASCO, US based healthcare services provider
- Nassau Life and Annuity Company, based in Connecticut
- National Student Clearinghouse, US based educational not for profit organization
- NavAXX S.A., Luxembourg based financial services company
- Nebraska State Colleges (Chadron State, Peru State and Wayne State) (impacted by NSC)
- NETSCOUT, US based software development company
- New Era Tech, multinational software development company
- New Mexico Military Institute (impacted by NSC)
- New Paltz University in New York (impacted by NSC, TIAA and Corebridge)
- New York Department of Education
- New York Life Insurance Company (impacted by EBS)
- New York Public Schools
- Norgren, global engineering company
- North College Idaho (impacted by NSC)
- North East Community College in Nebraska (impacted by NSC and TIAA)
- North Iowa Area Community College (impacted by NSC and TIAA)
- North Mississippi Health Services (impacted by Cadence)
- North of Superior Healthcare Group (impacted by BORN Ontario)
- North Park University in Chicago (possibly impacted by NSC)
- Northern Bank and Trust, based in Massachusetts
- Northern Oklahoma College (impacted by NSC)
- Northwestern Mutual, US based financial services provider
- Notable Frontier Sdn Bhd, IT consulting organization in Malaysia
- Nova Scotia Prescription Monitoring Program (NSPMP)
- NTT Data Americas (impacted by PBI)
- Nuance Communications, US based software company
- Nucor Corp, US based steel production company
- Oak Ridge Associated Universities, based in Oak Ridge, Tennessee
- Ofcom, UK’s media watchdog
- OKK, insurance company based in Switzerland
- Oklahoma State University (impacted by NSC, TIAA and United Healthcare Student Resources)
- Olympic College in Washington (impacted by NSC)
- Oregon Department of Transportation
- Oregon Health Plan (OHP) (impacted by PH Tech)
- Ottawa Hospital (impacted by BORN Ontario)
- Pace University in New York (impacted by NSC and TIAA)
- Pacific Premier Bank, California based bank
- Pan American Life Insurance Group, US based insurance organization
- Park National Bank, based in Chicago
- Paycom, US based payroll software provider
- Paycor, US based software development company
- PBI (Pension Benefit Information)
- Pear Tree Advisors, US based IT service provider
- Pear Tree Funds, financial institution in Massachusetts
- Peninsula College in Washington (impacted by NSC and TIAA)
- Pennsylvania Department of Human Services
- Pennsylvania Highlands Community College (impacted by NSC and TIAA)
- Performance Health Technology, US based health technology platform
- Peterborough Regional Health Centre (impacted by BORN Ontario)
- PH Tech, US based healthcare plan provider
- Piedmount Virginia Community College (impacted by NSC, TIAA and Corebridge)
- Pima County Health Department (impacted by Maximus)
- Pinnacle Claims Management, US based healthcare services provider
- Pioneer Electronics USA, subsidiary of Pioneer Corporation
- Plains Capital Bank (Hilltop Holdings), Texas based financial holding company
- PokerStars, world’s largest real money online poker site
- Pôle emploi, France’s national employment agency (impacted by Majorel)
- Postbank in Germany (impacted by Majorel)
- Power Financial Credit Union, South Florida based Credit Union
- PRA Group, US based debt collection agency
- Pratt Community College in Kansas (impacted by NSC)
- Premera Blue Cross, US based health insurance company (impacted by KERN)
- PRGX, Atlanta based financial services provider
- PricewaterhouseCoopers (PWC), global accounting firm.
- Primis Bank in Virginia (impacted by Darling Consultancy)
- Priority Partners, health insurance providers based in Maryland
- Progressive Casualty Insurance, based in Ohio
- Proskauer, multinational law firm
- Provinzial , German based insurance company
- Prudential Assurance Malaysia Berhad (PAMB), Malaysian insurance company
- Prudential BSN Takaful Berhad (PruBSN), Malaysian takaful company
- Prudential Insurance Company of America
- Putnam Investments, US based investment management firm
- Quark Software, US based software development company
- Quincy College in Massachusetts (impacted by NSC)
- Quinte Health (impacted by BORN Ontario)
- Quorum Federal Credit Union, based in New York
- Radisson Hotels Americas, part of Choice Hotels International
- Radius Global Solutions, US based debt collection agency
- RCI, US based travel, leisure and tourism company
- Realm IDx, California based biotechnology company
- Red River Bancshares, based in Louisiana
- Region of Queens Municipality, Canada
- Rensselaer Polytechnic Institute in New York (impacted by NSC)
- Repsol Sinopec Resources UK, oil and gas company based in Scotland
- Research Corporation of the University of Hawaii (impacted by TIAA)
- Rhenus Group, German logistics company
- Rhode Island Government
- Ricoh Acumen, US based legal services
- Rite Aid, US based pharmacy chain
- RiverSource Life Insurance Company, based in US
- Rockhurst University in Missouri (impacted by NSC and TIAA)
- Rockland Trust Bank, based in Massachusetts
- Rogers State University in Oklahoma (impacted by NSC)
- Rose State College in Oklahoma (impacted by NSC)
- Rutgers, The State University of New Jersey (impacted by NSC)
- Saint Francis Health System based in Tulsa, Oklahoma
- Saint Vincent College in Pennsylvania (impacted by NSC)
- Salelytics, US based consulting firm
- San Mateo County Community College District in California (impacted by NSC)
- Santa Clara University, based in California
- Sapiens International, computer software company based in Israel
- SAUL Trustee, UK based pension provider
- Schnabel Engineering, US based civil engineering company
- Schneider Electric, UK based energy equipment and solutions provider
- Scotiatrust, Canadian bank (impacted by EY)
- Serco, public services provider
- Shell, British multinational gas company
- Shoreline Community College in Washington (impacted by NSC and TIAA)
- Shutterfly, US based image sharing services
- SickKids, based in Toronto (impacted by BORN Ontario)
- Siemens Energy, energy development company based in Germany
- Siena College in New York (impacted by NSC and TIAA)
- Sierra Wireless, Canadian multinational wireless communication equipment manufacturer
- Skillsoft, US based educational technology company
- SLB, global technology company
- SMA Solar Technology, solar energy equipment supplier based in Germany
- SMC3, US based transportation software company
- Smurfit Kappa, UK packaging solutions company
- SNCF, France’s national state-owned railway company
- SoftTech, computer consultants based in the Netherlands
- Sony, Japanese electronics giant
- Sound Community Bank, commercial bank based in Washington
- South Utah University (impacted by NSC)
- Southern Cross Credit Union, based in Australia
- Southern Illinois University
- Sovos, US based software development company.
- Space Coast Credit Union in Florida
- Spalding University in Kentucky (impacted by NSC)
- Sparda-Banken, based in Germany
- St. Bernards Healthcare (impacted by Welltok)
- St Joseph’s Healthcare Hamilton (impacted by BORN Ontario)
- St Marys University in Texas (impacted by NSC)
- St Petersburg College in Florida (impacted by NSC)
- Starmount Life, US based life insurance company
- State of Maine
- State of Missouri
- State University of New York (impacted by TIAA, NSC and Corebridge)
- STIWA Group, Austrian manufacturing company
- Stockman Bank, Montana based community bank
- Stockton University in New Jersey (impacted by NSC and TIAA)
- Stony Brook University in New York (impacted by NSC, TIAA and Corebridge)
- Stratford Midwives, based in Ontario (impacted by BORN Ontario)
- Suffolk University in Boston (impacted by NSC)
- Sun Life Assurance Company Canada
- Sun Life Financial (impacted by PBI)
- SUNY Broome Community College in New York (impacted by NSC, TIAA and Corebridge)
- SUNY Polytechnic Institute in New York (impacted by NSC, TIAA and Corebridge)
- Sutter Senior Care, adult day care center in California
- Sutter Health, based in California
- Swiss Reinsurance Company, based in Zurich
- Synlab, French medical diagnostic service provider
- T. Rowe Price Retirement Plan Services
- Tacoma Community College in Washington (impacted by NSC and TIAA)
- Talcott Resolution, US based life insurance company
- TD Ameritrade, US based stock broker
- Teachers Insurance and Annuity Association of America
- Teachers Retirement System of Georgia (impacted by PBI)
- Teachers’ Retirement System of the City of New York (impacted by PBI)
- Telos, US based Information Technology company
- TELUS Health (US) based in Massachusetts
- Temple University in Pennsylvania (impacted by NSC and TIAA)
- Tennessee Consolidated Retirement System
- TenneT, Dutch power grid operator
- Texas Dow Employee Credit Union
- Texas Life Insurance Company
- The Centers for Medicare & Medicaid Services (CMS) (impacted by Maximus)
- The City University of New York (impacted by TIAA)
- The College of New Jersey (impacted by TIAA)
- The College of Wooster in Ohio (impacted by NSC and TIAA)
- The Estee Lauder Companies Inc, US based cosmetics company
- The Hallmark Channel
- The Harrington Group, not for profit organization based in Minnesota
- The Hartford, US based investment and insurance company
- The Masters University in California (impacted by NSC)
- The Midwife Clinic of East York Don-Mills (impacted by BORN Ontario)
- The University of Memphis in Tennessee (impacted by NSC)
- The University of Utah (impacted by TMG Health, TIAA and NSC)
- TJX Companies, American multinational retailer
- TMG Health, owned by Cognizant
- TomTom, Dutch multinational electronics manufacturer
- Toyota Boshoku Europe, European automotive manufacturing
- Transaction Applications Group (TAG), US based information technology services provider
- Transamerica Life Insurance based in Iowa
- TransPerfect, translation services based in New York
- Transport for London (TfL), UK government body
- Transylvania University in Kentucky (impacted by NSC)
- TrellisWare Technologies, US based telecommunications company
- Trico, US based automotive parts manufacturer
- Trinity College in Connecticut (impacted by NSC and TIAA)
- Trinity University in Texas (impacted by NSC and TIAA)
- TTI, US based electrical component distributor
- Tulsa Community College in Oklahoma
- UB Dental Clinic in Buffalo (impacted by Data Media Associates)
- UC Santa Cruz in California (impacted by NSC)
- UCLA, based in Los Angeles California
- UFCU, Texas based financial services organization
- Ulez and Congestion charges, UK toll accounting (impacted by TfL)
- Ummeed Housing Finance, Indian financial institution (impacted by Kotak Mahindra Life Insurance)
- Umpqua Bank, US based bank
- UNC Greensboro in North Carolina (impacted by NSC)
- Union Bank and Trust Company, US based privately owned state chartered commercial bank.
- United Bank, based in US
- United HealthCare Services, US based health insurance firm
- United Regional Healthcare System, healthcare organization based in Texas
- UnitedHealthcare Student Resources
- Universal Federal Credit Union, based in West Virginia
- University at Buffalo in New York (impacted by Corebridge, NSC, TIAA and UnitedHealthcare)
- University Federal Credit Union, based in Texas
- University of Alaska (impacted by NSC)
- University of Central Oklahoma (impacted by NSC)
- University of Colorado (impacted by NSC, TIAA and UnitedHealthcare)
- University of Dayton in Ohio (impacted by NSC)
- University of Delaware (impacted by NSC and TIAA)
- University of Georgia, based in Athens, Georgia
- University of Idaho (impacted by NSC)
- University of Illinois (impacted by NSC)
- University of Massachusetts Medical School
- University of Michigan (impacted by PBI and TIAA)
- University of Missouri System (impacted by PBI and NSC)
- University of Missouri, based in Columbia, Missouri
- University of North Dakota (impacted by TIAA and NSC)
- University of Northern Colorado (impacted by NSC and TIAA)
- University of Oklahoma (impacted by NSC and TIAA)
- University of Rochester, based in Rochester, New York
- University of Texas Southwestern Medical Center
- University System of Georgia
- Unum Group, insurance company based in Tennessee
- UofL Health, Kentucky based regional academic health system
- US Department of Agriculture
- US Department of Energy’s Waste Isolation Pilot Plant
- US Department of Health and Human Resources
- US Office of Personnel Management (OPM)
- UT Southwestern Medical Center
- Utah State University (impacted by NSC, TIAA and The Hartford)
- Utah Tech University (impacted by NSC)
- VALIC Retirement Services Company based in Texas (impacted by PBI)
- Valley Bank, based in New Jersey
- Valmet, software company based in Finland
- Vassar College in New York (impacted by TIAA)
- Vecino Health Centers in Texas (impacted by Harris Health)
- Ventiv Technology, US based IT services provider
- Vericast, Texas based advertising services agency
- Vericity Inc, insurance providers based in Illinois (impacted by PBI)
- Verivox, German comparison shopping website
- Verlagsgesellschaft Vogelsberg GmbH & Co, Germany based publishing company.
- Vermont State Colleges System (impacted by TIAA ad NSC)
- Victoria College in Texas (impacted by NSC)
- Virgin Pulse, health and wellbeing organization
- Virginia Community College System (impacted by NSC and TIAA)
- Virginia Community School System (impacted by NSC)
- Virginia Military Institute (impacted by NSC)
- Virginia Retirement System (impacted by PBI)
- VisionWare
- Vitality Group
- Vitesco Technologies Group, German automotive supplier
- VNS Health Health Plans in New York (impacted by TMG Health)
- VOSS Fluid, EU based manufacturer
- VRM Service, German media company
- Wake Forest University in North Carolina (impacted by TIAA)
- Walker Die Casting, Foundry in Tennessee
- Washington National Insurance Company (impacted by PBI)
- Washington State University (impacted by NSC and TIAA)
- Wayne College in Nebraska (impacted by NSC)
- Webster University in Missouri (impacted by TIAA and NSC)
- WEC Energy, based in Wisconsin
- Welltok, a Virgin Pulse-owned healthcare platform
- West Parry Sound Health Centre (impacted by BORN Ontario)
- Westamerica Bank based in California
- Westat, US based professional services company
- Western Oklahoma State College (impacted by NSC)
- Western University of Health Sciences in California (impacted by NSC and TIAA)
- Western Washington University (impacted by NSC and TIAA)
- Whatcom Community College in Washington (impacted by NSC and TIAA)
- William & Mary University in Virginia (impacted by NSC and TIAA)
- Willis Towers Watson, London based insurance company
- Wilmington College in Ohio (impacted by NSC)
- Wilton Reassurance Company, US based life insurance agency
- Wolters Kluwer, Dutch information services company
- Worcester State University in Massachusetts (impacted by NSC)
- Xavier University in Ohio (impacted by NSC)
- Yakima Valley College in Washington (impacted by NSC and TIAA)
- Yakult Philippines, food and beverage manufacturer
- Zellis, UK based software development company.
- Zurich Insurance
Last update: 20th November
Please note that various different information sources have been used to collate the list of organizations above.
Related Posts
The State of Ransomware 2024
BlackFog's state of ransomware report measures publicly disclosed and non-disclosed attacks globally.
CDK Global Ransomware: What Happened and How It Impacted Businesses
Here you will learn about the CDK Global ransomware attack, the impact on auto dealerships, relevant recovery steps and general cybersecurity practices for businesses.
Ransomware Containment: Effective Strategies to Protect Your Business
Discover effective ransomware containment strategies for your business. This guide discusses network segmentation, zero trust, and practical best practices for IT managers and cybersecurity professionals to reduce ransomware damage.
Ransomware Meets Retail: Sainsbury’s, Starbucks and Morrisons Feel the Heat from Blue Yonder Attack
The Blue Yonder ransomware attack disrupted major retailers like Sainsbury’s, Starbucks, and Morrisons, highlighting the vulnerabilities of global supply chains and the urgent need for stronger cybersecurity defenses.
Top 5 Cyberattacks During Black Friday and Thanksgiving
Find out about the top five biggest cyberattacks for Black Friday and Thanksgiving, from data breaches and ransomware, to see the risks businesses experience during the holidays.
Healthcare Ransomware Attacks: How to Prevent and Respond Effectively
Learn how to protect yourself from healthcare ransomware attacks. We discuss the main security weaknesses, suggest security steps, and offer possible means of protecting patient information.