US authorities offer up to $10M for info on Clop ransomware

The US State Department is offering a reward of up to $10 million for information connecting the Clop ransomware gang or any other malicious cyber actors targeting US critical infrastructure to a foreign government.

“Do you have info linking CL0P Ransomware Gang or any other malicious cyber actors targeting U.S. critical infrastructure to a foreign government? Send us a tip. You could be eligible for a reward,” reads a message in the official State Department’s Rewards for Justice program Twitter account.

Clop (Cl0p) is a variant of the CryptoMix ransomware family first spotted in 2019 that operates on a ransomware-as-a-service (RaaS) model. The malware is widely believed to have emerged from Russian cybercriminal circles and is frequently leveraged by several Russian affiliates, among them the FIN11 financially motivated hacking group.

Over the past few years, the Clop ransomware gang gained notoriety for compromising high-profile organizations in various industries worldwide using multilevel extortion techniques. In 2023, the group claimed responsibility for the GoAnywhere zero-day attacks that affected more than a hundred organizations across the world, and the MOVEit global mass hack that impacted US government agencies, oil and gas giant Shell, UK’s media regulator Ofcom, British integrated communications provider Adare SEC, and many other organizations.

Back to the list

Latest Posts

Cyber Security Week in Review: January 16, 2026

In brief: Microsoft fixes a Windows zero-day flaw, Russian hackers target Ukraine posing as charities, and more.
16 January 2026

RedVDS cybercrime platform disrupted in global takedown

RedVDS sold access to disposable virtual Windows servers for as little as $24 a month, allowing criminals to run fraud and phishing operations at scale.
15 January 2026

Administrator of AVCheck malware testing service arrested in the Netherlands

The man is suspected of facilitating cybercrime by allowing malware devs to test whether their software could bypass antivirus protections.
15 January 2026