On December 24, 2024, the Clop ransomware group added Icertis to its leak site, announcing it had obtained internal files from the contract-lifecycle-management company and that it possesses data belonging to many organizations that use Cleo software.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch iceri#####
Get alerted the next time iceri##### files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about iceri#####’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Incident
Public reporting indicates the listing appeared on the Clop leak site on Christmas Eve. The group claims to have exfiltrated internal files during a ransomware attack on Icertis. It also states it holds data from multiple companies that rely on Cleo file-transfer software and says its teams are contacting victims directly to arrange private chats. The exact number of Icertis records exposed remains unknown, and no sample data has been publicly released. Available reporting describes the incident as part of Clop’s ongoing campaign targeting organizations that use specific file-transfer tools.
Why This Matters for You and Your Family
When a business supplier or software provider is breached, your personal information can be caught in the net. Icertis helps companies manage contracts that often contain employee names, addresses, Social Security numbers, payment details, and family contact information. If your employer or a company you deal with uses Icertis or Cleo, your data may already be in attackers’ hands. Credential leaks like this one frequently spread to consumer accounts, allowing criminals to reset passwords on email, banking, or shopping sites that reuse the same login details. For families this can mean sudden identity theft, surprise bills, or strangers contacting your children online using information pulled from the breach.
The Doxxing and Identity-Chain Risk
A single corporate breach rarely stops at the company. Attackers map connections between work emails, personal accounts, phone numbers, and online handles. Once they link your work record to a gaming username or family social-media profile, they can launch targeted doxxing attacks or sell the full identity chain on underground markets. Children’s gaming accounts are especially vulnerable because kids often reuse simple passwords or email addresses tied to family data. Public reporting shows these chains allow criminals to move from one compromised account to many others within hours.