# Clop Ransomware Claims Zebra Technologies Breach

Published: 2026-08-14 · Severity: elevated · Sectors: manufacturing, technology
Canonical: https://vorant.io/reports/349f4c1d-9eb2-564c-ab94-3447269bb296/clop-ransomware-claims-zebra-technologies-breach

> The Clop ransomware group added a victim matching Zebra Technologies to its leak site, claiming 8TB of exfiltrated data.

Ransomware.live logged a new Clop victim listing on 2026-08-14, claiming exfiltration of roughly 8TB of data including databases, project files, and CAD files. DNS and SPF records embedded in the listing (referencing zebra.com mail infrastructure and SPF includes) indicate the victim is Zebra Technologies, a hardware/enterprise technology manufacturer with a stated revenue of approximately $5.6 billion.

The posting is consistent with Clop's typical double-extortion pattern of publishing partial victim details and a data sample summary to pressure payment. No technical intrusion vector, malware sample, or exploited vulnerability is disclosed in this listing; the entry consists primarily of victim identification metadata (WHOIS/DNS/SASL records) rather than technical indicators of compromise.

Given the absence of confirmed exploitation details or corroborating incident disclosure from the named organization, this should be treated as an unverified leak-site claim pending further confirmation, though Clop's historical track record lends it credibility.

## Mentioned in this report

- Threat actors: Clop
- Malware: Clop

Source reporting: https://www.ransomware.live/id/WkVCUkEuQ09NQGNsb3A=

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/349f4c1d-9eb2-564c-ab94-3447269bb296/clop-ransomware-claims-zebra-technologies-breach.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
