Ransomware victim disclosure
← All victimsUnknown Company (12.9M Salesforce records / Data Center)
Claimed by Clop · listed 2 hours ago
Status timeline
- ListedSep 20, 2026
Current state: Listed for ransom
At a glance
- Group
- Clop
- Status
- Listed for ransom
- Listed on leak site
- Sep 20, 2026
- Data size
- 645GB uncompressed (Sharepoint)
- Records
- 12,900,000+
About the victim
AI dossier — public-source company profileAn organization operating data centers with significant Salesforce and SharePoint infrastructure. The victim name references 12.9M Salesforce records and a data center, suggesting a large enterprise with critical infrastructure responsibilities, physical security operations, and multi-regional presence.
- Industry
- Data Center Operations / Critical Infrastructure
Attack summary
Severity: critical — Confirmed exfiltration of massive scale PII (182K+ customer records, 8.3K+ employee records with full identifiers), regulated data (contracts, compliance materials), and critically sensitive infrastructure intelligence (data center schematics, access control systems, security policies, credential artifacts). The latter represents direct threat to physical and operational security of critical infrastructure.CLOP claims to have exfiltrated 12.9 million Salesforce records and 645GB of uncompressed SharePoint data (288,729 files). Compromised data includes customer PII, employee information, contracts, data center infrastructure drawings, security policies, access credentials, and physical security artifacts. The group demanded $13 million and threatened public disclosure on 24 Aug 2026 (later extended to 16 Sep 2026).
Data the group says was taken
AI dossier — extracted from the leak post- 12.9M Salesforce records
- 182,000+ customer contact records
- 8,300+ employee PII records
- Executed contracts, MSAs, NDAs, amendments, leases, SOWs
- Physical key inventory and verification photos
- Data center drawings, floor plans, electrical diagrams
- Security system schematics
- CERM (Critical Environment Reliability Management) processes
- Physical and information security policies
- Credential artifacts (PasswordList.xlsx, Okta access lists, badge reports)
- Data center access control forms
What the group claims
Company refused to pay a $13 million demand. 12.9 million Salesforce records compromised along with 369.6 GB compressed / 645 GB uncompressed Sharepoint data including customer data, employee PII, contracts, MSAs, NDAs, data center drawings, security policies, and credential/access-control artifacts.
The leak post
captured from the group's site**IF YOU WANT TO SAVE YOUR BRAND AND NOT DIE BY MY HANDS:** Email us from your official email at [email protected] and lets see how rich you really are. 2.333% of my networth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism. We are aware of the situation involving a number of our CDNs being unreachable. We are working on restoring them. We estimate 24 to 48 hours till they are back. 91.215.85.22 remains accessible and usable. **Update, July 27, 3:01 a.m. ET:** All CDN mirrors are back online; however, content synchronization across all three mirrors is still ongoing. Addicionally, we are still working on preparing the release of the torrents. We kindly ask our visitors to seed once they become available. A notification will be posted upon release. All CDN mirrors are currently experiencing a service disruption. **All files are fully backed up and no data has been lost.** At this time we do not have an estimated time of resolution.We are working to restore service promptly and will share updates as they become avail…
Data the group says was taken
- PII
- Salesforce records
- Sharepoint data
- customer data
- employee data
- contracts
- NDAs
- MSAs
- SOWs
- security policies
- credentials
- access control data
- data center schematics
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

