VORANT. Threat Intelligence Sign in Get the full feed

Clop lists Toast Inc on leak site

high threat technologyretail

Ransomware group Clop claims to have compromised restaurant tech provider Toast (toasttab.com), listing employee and user data on its leak site.

Ransomware.live tracking data indicates the Clop ransomware group has added Toast, Inc. (toasttab.com) to its victim leak site, claiming compromise of the US-based restaurant technology and point-of-sale software provider. The listing reports 9 compromised employee accounts, 6,928 compromised user records, 20 third-party employee credentials, and a 105-point external attack surface, alongside enumerated DNS, MX, and TXT records tied to the domain.

Toast provides cloud-based POS, payment processing, and restaurant management software used broadly across the US food service industry, making any confirmed data exposure relevant to a large customer base. No specific initial access vector, exfiltrated data samples, or ransom demand details are provided in this listing beyond the claim itself; the entry appears to be a standard leak-site posting rather than a technical disclosure. Given Clop's history of large-scale data theft via vulnerability exploitation (e.g., MOVEit, GoAnywhere), organizations using Toast's platform should monitor for further disclosures and verify their own exposure through third-party risk channels.

Mentioned in this report

Threat actors Clop

Source reporting: https://www.ransomware.live/id/VE9BU1RUQUIuQ09NQGNsb3A=

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free