MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Accellion FTA zero‑days enable mass data theft

Beginning 23/12/2020, attackers exploited multiple zero‑day vulnerabilities in ACCELLION’s legacy File Transfer Appliance (FTA), installing the DEWMODE web shell to exfiltrate files from customer‑hosted FTA servers. Dozens of organizations across Australia, Canada, New Zealand, Singapore, the UK, and the US disclosed data theft, with data surfacing on the CLOP leaks site. Accellion urged customers to migrate off FTA and issued patches. U.S. retailer KROGER reported compromise via the vulnerable service, illustrating downstream customer impact.

70

Estimated severity

70 / 100

90

Source reliability

90 / 100

Approximate Date

23/12/2020

Targeted Company

ACCELLION

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

KROGER (Software vendor)

Geographic Impact

Country Targeted Company

United States

USA

Other Affected Countries

Australia

AUS

Canada

CAN

New Zealand

NZL

Singapore

SGP

United Kingdom

GBR

Target country

United States

Affected countries

AustraliaCanadaNew ZealandSingaporeUnited KingdomUnited States

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactService unavailabilityDownstream customer disruption

Affected sectors

Technology & IT ServicesRetail

Affected departments

Information Technology

Attack Profile

Attack types

Zero-day exploitationSQL injectionData exfiltrationData breach

Attributed threat actors

CLOP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.