jomar##### Listed by clop Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
jomar##### was listed by the clop ransomware group on December 24, 2024, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check the company’s notices and consider changing passwords or enabling extra security steps if your data could be involved.
Ransomware groups continue to exploit widely used file-transfer and business software, turning supply-chain tools into vectors for mass data theft. In late 2024, the Clop ransomware group publicly listed additional organisations it claims to have compromised through such channels, adding pressure on companies that rely on those platforms.
On 24 December 2024, the organisation known as jomar##### (presumed full name JOMARSOFTCORP) appeared on Clop’s leak site. The group asserts that it exfiltrated internal files during a ransomware attack and has begun contacting affected companies. Public detail remains limited; the number of people affected is unknown, and no independent confirmation of the claim has been released.
What happened
According to the listing dated 24 December 2024, Clop claims jomar##### as a victim. The group’s announcement states that it holds data from many companies that use Cleo software and that its teams are reaching out to those organisations with a “special secret chat.” The only data type named as exposed is internal files said to have been exfiltrated in a ransomware attack. No file counts, exact dates of intrusion, technical method of entry, or ransom demand have been disclosed in the available record. The listing itself constitutes an unverified claim by the threat actor.
Inside clop
Clop (also styled Cl0p) is a long-running ransomware operation that specialises in large-scale data theft followed by public extortion. The group typically gains access through vulnerabilities in widely deployed enterprise software, steals sensitive files, and then posts victim names on a dedicated leak site if payment is not made. Its earlier campaigns against managed file-transfer products demonstrated a pattern of rapid exploitation of zero-day or newly disclosed flaws, followed by mass victim notifications. Clop’s public statements about any individual organisation, including jomar#####, remain claims until corroborated by the victim or independent investigators.
About jomar#####
jomar#####, referenced in the Clop announcement as JOMARSOFTCORP, appears to be a software or technology firm. Organisations of this type commonly develop, distribute or integrate business applications and therefore hold internal source code, customer records, contracts, employee data and configuration files for the systems they support. Because the Clop listing specifically references companies that use Cleo file-transfer software, a breach at such a firm can affect not only its own operations but also the clients and partners that rely on its products or services. The precise nature of jomar#####’s business and customer base has not been detailed in the public breach record.
What was likely exposed
The available facts state only that internal files were exfiltrated. No inventory of those files, no confirmation of personal data, financial records or intellectual property, and no count of affected individuals have been released. Organisations in the software sector typically store source repositories, customer databases, employee directories, authentication credentials and operational documentation. Whether any of those categories were among the files Clop claims to hold remains unconfirmed. Readers should treat the exact contents as undisclosed.
Why it matters
If the claim is accurate, individuals whose information resided in the stolen files face risks of identity misuse, targeted phishing or further social-engineering attacks that leverage the leaked material. For the organisation itself, the exposure of internal files can disrupt operations, damage commercial relationships and trigger regulatory notification duties once the scope is verified. Because Clop has a history of publishing stolen data when negotiations stall, the mere listing already creates reputational and operational pressure even before any files appear online. The absence of confirmed numbers of people affected means the full human impact cannot yet be quantified.
If your data was in this claimed breach
Monitor financial and email accounts for unusual activity and enable multi-factor authentication wherever possible. Consider placing a fraud alert with credit bureaus if you believe personal identifiers may have been involved. Change passwords on any systems that may have shared credentials with the affected environment. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets. Official confirmation from jomar##### or law-enforcement agencies, when available, will provide the most reliable guidance on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
calex##### Listed by clop Ransomware Groupwhitm##### Listed by clop Ransomware Grouppolar##### Listed by clop Ransomware Groupcree##### Listed by clop Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the jomar##### Listed by clop Ransomware Group →
Publicly posted by clop — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.