United States
USA
Beginning 23/12/2020, attackers exploited multiple zero‑day vulnerabilities in ACCELLION’s legacy File Transfer Appliance (FTA), installing the DEWMODE web shell to exfiltrate files from customer‑hosted FTA servers. Dozens of organizations across Australia, Canada, New Zealand, Singapore, the UK, and the US disclosed data theft, with data surfacing on the CLOP leaks site. Accellion urged customers to migrate off FTA and issued patches. U.S. retailer KROGER reported compromise via the vulnerable service, illustrating downstream customer impact.
Estimated severity
70 / 100
Source reliability
90 / 100
Approximate Date
23/12/2020
Targeted Company
ACCELLION
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
United States
USA
Australia
AUS
Canada
CAN
New Zealand
NZL
Singapore
SGP
United Kingdom
GBR
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone