Clop ransomware claims Fiserv as victim
The Clop ransomware group listed fintech giant Fiserv as a victim, claiming compromise of thousands of user accounts and exposed FortiOS VPN credentials.
Ransomware.live's tracking indicates the Clop ransomware group added Fiserv, a major U.S. financial technology provider, to its victim list on 2026-08-12. Fiserv supplies core banking, payment processing, and card services to banks and credit unions globally, making any confirmed compromise of its environment significant given downstream exposure to financial institutions.
According to the listing, the claimed breach includes 4 compromised employee accounts, 1,064 compromised user accounts, 170 third-party employee credentials, and a sizeable external attack surface (104 assets). Notably, the domain's FortiOS SSL-VPN credentials were reportedly exposed via the "FortiBleed" vulnerability (CVE-2022-40684), an authentication bypass in FortiOS/FortiProxy that has been exploited in numerous intrusions since 2022. The presence of numerous third-party SaaS domain-verification records (Microsoft 365, Cisco Webex, Atlassian, DocuSign, Salesforce, etc.) reflects the breadth of Fiserv's cloud service footprint but does not itself indicate compromise of those platforms.
No stolen data samples, malware binaries, or C2 infrastructure are referenced in this listing beyond the ransomware group's claim page. Given Clop's history of large-scale extortion campaigns (including MOVEit, GoAnywhere, and Accellion exploitation) and the sensitivity of the financial services sector, this listing warrants monitoring, though it should be treated as an unconfirmed leak-site claim pending independent verification.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/RklTRVJWLkNPTUBjbG9w
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free