The gang behind the Clop ransomware claims to have stolen 2 million credit cards from E-Land Retail.
E-Land Retail, a subsidiary of E-Land Global, owns several clothing stores, including New Core and NC Department Store.

Late last month, E-Land Retail was forced to close 23 of its stores due to a ransomware attack by the CLOP gang.
At the time, E-Land had said in a statement that sensitive data customer as it was encrypted on another server.
“Although this ransomware attack caused some damage to network and systems, customer information and sensitive data are encrypted on a separate server,” E-Land Retail CEO Chang-Hyun Seok said in a statement on the company’s website.
However, in an interview with BleepingComputer, the operators of the CLOP ransomware claimed that they breached E-Land a year ago and all the while were stealing credit cards using a POS malware they had installed on the company's network.
“A year ago, we hacked their network. We thought about what to do, we installed POS malware and left it for a year. Before the ransomware, the credit cards were collected. For a whole year the company didn’t suspect anything and did nothing,” the CLOP gang told BleepingComputer.

Using POS malware, the CLOP ransomware gang said it stole 2 million credit card details
POS malware is used to scan the memory of POS terminals as credit card transactions are made. When data , the malware copies the information as Track 1 or Track 2 data and transmits it to the criminals' server.
The credit cards that the CLOP gang claims to have stolen are in the form of Track 2 data, which includes the credit card number, expiration date, and other information. However, it does not contain the credit card's CVV code. Therefore, hackers can only use it to create fake credit cards for in-store purchases.
E-Land has not yet commented on the hackers' claims.
