VORANT. Threat Intelligence Sign in Get the full feed

Clop Ransomware Claims Zebra Technologies Breach

elevated threat manufacturingtechnology

The Clop ransomware group added a victim matching Zebra Technologies to its leak site, claiming 8TB of exfiltrated data.

Ransomware.live logged a new Clop victim listing on 2026-08-14, claiming exfiltration of roughly 8TB of data including databases, project files, and CAD files. DNS and SPF records embedded in the listing (referencing zebra.com mail infrastructure and SPF includes) indicate the victim is Zebra Technologies, a hardware/enterprise technology manufacturer with a stated revenue of approximately $5.6 billion.

The posting is consistent with Clop's typical double-extortion pattern of publishing partial victim details and a data sample summary to pressure payment. No technical intrusion vector, malware sample, or exploited vulnerability is disclosed in this listing; the entry consists primarily of victim identification metadata (WHOIS/DNS/SASL records) rather than technical indicators of compromise.

Given the absence of confirmed exploitation details or corroborating incident disclosure from the named organization, this should be treated as an unverified leak-site claim pending further confirmation, though Clop's historical track record lends it credibility.

Mentioned in this report

Threat actors Clop
Malware Clop

Source reporting: https://www.ransomware.live/id/WkVCUkEuQ09NQGNsb3A=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free