2023 Atos — Cl0p GoAnywhere MFT zero-day; data from acquired-entity backup folder
Data compromised
Unspecified archival content in impacted backup scope per vendor statement
Technical writeup
Atos issued a March 2023 security statement confirming that the Cl0p ransomware group exploited a Fortra GoAnywhere MFT zero-day to steal material from a backup folder tied to a recently acquired business unit (reporting often names Nimbix-era contexts), while stressing ongoing investigation and remediation. SecurityWeek linked the disclosure to the broader early-2023 GoAnywhere victim wave.
Root cause
Critical MFT software vulnerability exploited for remote code execution and bulk file theft