Oddbean new post about | logout
 Back in June, the Clop gang began releasing some of the data from the MOVEit hacks as torrent files after it began having problems with its hosting infrastructure.

Researchers from Palo Alto Networks have analyzed the seeds of the Clop torrent files and found that most of the stolen MOVEit files have been released through three IP addresses belonging to Moscow-based web hosting provider FlyServers.

https://unit42.paloaltonetworks.com/cl0p-group-distributes-ransomware-data-with-torrents/