Kellogg’s leaks sensitive data after Clop attack


WK Kellogg, the company behind the Kellogg’s cereals, has been hit by a major data breach. Cybercriminals from the ransomware group Clop exploited a vulnerability in the software of an external supplier, stealing employees’ personal data.

The data breach took place in December 2024, when data was stolen from the file transfer service Cleo. At the time, Cleo suffered a wave of attacks from Clop. The ransomware gang used zero days to gain access to Cleo servers. Then, on February 27, 2025, Kellogg’s discovered that the attacks may have affected it. The cereal manufacturer used third-party Cleo servers to transfer personnel files to HR service providers, and the attack targeted precisely these servers.

Read more…
Source: Techzine News


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Detroit Car Makers Allegedly Hacked, Names and Social Security Numbers Stolen

    January 13, 2017

    Detroit’s Big Three automakers are the latest big companies to become victims of hackers, with a new report now claiming that employees’ names and social security numbers might have been exposed during a breach. Details are very sketchy at the moment, and there is no confirmation from the involved companies, but according to the 7 Action ...

  • 11 Gigabytes of Sensitive Data Belonging to US DoD Staff Exposed

    January 5, 2017

    Personal details of doctors who are deployed in the United States Special Operations Command (USSOCOM or SOCOM) have been exposed due to a security vulnerability discovered in a server operated by health services contractor Potomac Healthcare Solutions. MacKeeper Security Researcher Chris Vickery discovered in late December that Potomac, which provides healthcare workers to the government through ...