
The Indian group Indiabulls Group was attacked by the operators of the CLOP Ransomware. The attack resulted in the leak of screenshots with stolen data. It is an Indian group with revenues of $ 3.5 billion (2019), more than 19,000 employees and subsidiaries operating in various sectors.
CLOP Ransomware claims it has breached the Indiabulls Group
The operators of the CLOP Ransomware claimed to have breached Indiabulls and published screenshots of the files they stole during the attack.
The CLOP gang is one of the ransomware groups that steals data before encrypting it. They then publish the stolen files on the data leak site "CL0P ^ _- LEAKS" and threaten to publish even more data if victims do not pay the ransom.
The hackers published screenshots of six stolen Indiabulls Group files, leaving the message “Contact us within 24 hours.”
The leaked data includes various documents and four spreadsheets related to Indiabulls' subsidiaries, Indiabulls Pharmaceuticals and Indiabulls Housing Finance Limited.

No information has yet been leaked regarding the amount of money demanded by the ransomware gang. We also don't know exactly when the attack.
Security firm Bad Packets , however, said that Indiabulls Group has an exposed Citrix Netscaler ADC VPN gateway, which is vulnerable to the CVE-2019-19781. Therefore, the initial breach may have been done this way, although this has not yet been proven.
Additionally, Bad Packets said its internet scans had revealed last year that the group had long-term out-of-date servers, meaning systems were vulnerable to attack.
In March, the operators of the CLOP Ransomware also carried out an attack on the American pharmaceutical company ExecuPharm. The hackers stole a huge amount of data (163 GB) and exposed it on the leak site because the victim did not pay the ransom.
