sully##### Listed by clop Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
sully##### was listed by the clop ransomware group on December 24, 2024, after internal files were exfiltrated in a ransomware attack. Anyone connected to sully##### should verify whether their information was exposed and take steps to protect their accounts.
Ransomware groups continue to pressure large professional-services firms by claiming theft of internal files and threatening public release. In that landscape, a late-2024 listing attributed to the clop group has drawn attention to an organisation identified as sully#####.
Public reporting on 24 December 2024 stated that clop had listed sully##### and claimed to have exfiltrated internal files. The number of people affected remains unknown, and independent confirmation of the claim has not been published. The incident matters because law-firm and professional-services data often include privileged client material; any confirmed exposure would raise concrete confidentiality and regulatory questions.
Breaking down the breach
According to the available record, sully##### was listed by the clop ransomware group on or about 24 December 2024. The group’s announcement described the organisation as a presumed victim and stated that internal files had been exfiltrated in a ransomware attack. The same notice asserted that the group holds data from many companies that use Cleo software and that its teams were contacting the company to provide a “special secret chat.”
No public figure has been given for the volume of data, the number of files, or the number of individuals whose information may be involved. The precise method of initial access, the duration of any intrusion, and whether encryption was also deployed remain undisclosed. The listing itself is a claim by the group; it has not been independently verified in the material provided.
Who is clop?
Clop (also styled Cl0p) is a long-running ransomware operation known for double-extortion tactics: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if a ransom is not paid. The group has repeatedly targeted organisations that rely on widely used file-transfer and managed-file-transfer products, publicising victim names to increase pressure. Its public statements frequently invite victims into private negotiation channels.
In this case the group’s own wording links the claimed data to companies that use Cleo. That claim is consistent with clop’s established pattern of exploiting software supply-chain or transfer-tool vulnerabilities, but the facts do not confirm that any specific vulnerability was used against sully#####. All statements about what the group holds regarding this organisation remain unverified claims.
sully##### and its sector
The organisation is identified in the record as sully#####; the clop announcement itself refers to a presumed victim name of Sullivan & Cromwell. Sullivan & Cromwell is a well-known international law firm that advises corporations, financial institutions and governments on mergers, litigation, regulatory matters and other sensitive transactions. Firms of this type routinely hold privileged correspondence, deal documents, personal data of clients and employees, and confidential commercial information.
A breach affecting such an organisation is consequential because the data are often protected by attorney-client privilege and by professional and regulatory confidentiality rules. Even an unconfirmed listing can create uncertainty for clients and counterparties who must decide whether to treat their own information as potentially compromised.
What was likely exposed
The only data type named in the public record is “internal files” said to have been exfiltrated in a ransomware attack. No further inventory—file names, categories, or volume—has been disclosed. Organisations of this kind typically maintain client matter files, correspondence, billing records, employee information and internal administrative documents. Whether any of those categories were among the claimed files is unconfirmed.
Because the exact contents remain undisclosed, the following points summarise only what is known or what is typical rather than proven:
- Named exposure: internal files (claim by clop).
- People affected: unknown.
- Specific document types, personal data fields or client identities: not disclosed.
- Any confirmation that the files actually originated from sully#####: not present in the public record.
What's at stake
For individuals whose information may appear in internal firm files, the practical risks include unwanted contact, phishing that leverages accurate personal or professional details, and potential misuse of identity or financial data if such material was present. For corporate clients, the principal concern is the possible compromise of privileged or commercially sensitive material that could affect ongoing transactions or litigation strategy.
For the organisation itself, the stakes include the need to investigate the claim, notify clients and regulators where required, and manage reputational and contractual consequences. Because the scale and content of any exfiltration remain unconfirmed, the actual impact cannot yet be quantified. The listing alone, however, is sufficient to trigger internal review and external communication obligations in many jurisdictions.
Were you affected?
If you are a client, employee or counterparty of the organisation, treat any unexpected communication that references this incident with caution. Monitor accounts for unusual activity, enable multi-factor authentication where available, and consider placing fraud alerts with credit bureaus if you believe personal financial data could be involved. Official notifications, if any, will come from the organisation or from regulators; do not rely solely on claims published by threat actors.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan does not confirm or rule out involvement in this specific incident, but it provides a practical starting point for personal vigilance while further facts, if any, become public.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
thoms##### Listed by clop Ransomware GroupHUDSONEXECUTIVE.COM Listed by clop Ransomware GroupTHEMORTGAGEFIRM.COM Listed by clop Ransomware GroupKLMEQUITIES.COM Listed by clop Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the sully##### Listed by clop Ransomware Group →
Publicly posted by clop — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.