Qualys Joins List of Accellion FTA Victims After Zero-Day Exploitation
Cybersecurity firm Qualys has confirmed it was the latest victim of an Accellion FTA server breach exploiting a zero-day vulnerability. The disclosure adds Qualys to a growing list of organizations targeted by the Clop ransomware gang through the file-sharing application's flaw. The breach was first identified in December 2020, with the Clop gang subsequently posting screenshots of Qualys documents on their data leak site.
How the Zero-Day Exploit Worked
The Accellion FTA server runs on outdated technology that lacks modern security controls. Attackers exploited a vulnerability in the file-transfer application to gain unauthorized access to stored files. Since Accellion FTA devices are designed to exist outside the primary security perimeter and be publicly accessible, the attack vector required no internal network penetration. The zero-day allowed attackers to extract databases, configuration files, and other sensitive information stored on the server host.
Clop Ransomware's Extortion Model
Following the initial breach, the Clop ransomware gang demands payment in exchange for not publishing stolen data. Victims receive ransom notes demanding cryptocurrency in return for deletion of the exfiltrated files. The gang operates a leak site where they post samples of compromised data to prove possession and pressure victims into paying. Before Qualys's admission, known victims included Transport for NSW, Singtel, Bombardier, Fugro, the law firm Jones Day, science and technology company Danaher, and technical services company ABS Group.
Qualys' Prior Exposure and Response
Qualys deployed its Accellion FTA server at fts-na.qualys.com, with the server IP assigned to Qualys's network range. The company had positioned the device in a segregated DMZ environment, completely separate from systems that host and support Qualys products. This architectural choice limited the breach's scope — Qualys confirmed no impact on production environments, codebase, or customer data hosted on the Qualys Cloud Platform. All Qualys platforms continued functioning fully with no operational impact at any time.
In response to the confirmed breach, Qualys has taken several mitigation steps. The organization has shut down the affected Accellion FTA servers and switched to alternative applications for support-related file transfers. Qualys is still investigating the breach and has hired Mandiant, a prominent incident response firm, to assist with the inquiry. The company disclosed the incident in a security incident notice published today, stating that new information had emerged about the previously identified zero-day exploit in the third-party Accellion FTA solution.
Official Statement from Qualys
"New information has come out today related to a previously identified zero-day exploit in a third-party solution, Accellion FTA, that Qualys deployed to transfer information as part of our customer support system," the company stated in its security incident notice. "Qualys has confirmed that there is no impact on the Qualys production environments, codebase or customer data hosted on the Qualys Cloud Platform. All Qualys platforms continue to be fully functional and at no time was there any operational impact." The statement added that Qualys had deployed the Accellion FTA server in a segregated DMZ environment, completely separate from systems that host and support Qualys products, used solely to transfer information as part of the customer support system.
Qualys also confirmed it has decommissioned the affected FTA devices. Shodan data shows the server was last active on February 18th, 2021. The company states it has switched to alternative applications for support-related file transfers while the investigation continues.
Prior Victims of the Clop Campaign
The Clop ransomware gang's extortion campaign predates the Qualys disclosure by several months. The full list of victims named prior to this announcement includes:
- Transport for NSW, the government agency for New South Wales, Australia
- Singtel, the telecommunications provider based in Singapore
- Bombardier, the aerospace and transportation company
- Fugro, the geo-data specialist
- Law firm Jones Day
- Science and technology company Danaher
- Technical services company ABS Group
Each of these organizations experienced similar file theft via the Accellion FTA zero-day, followed by Clop ransom demands and data leak site posting.
Industry Implications and Lessons Learned
The Qualys breach highlights ongoing risks associated with legacy file-transfer applications. The Accellion FTA zero-day exploit has proven particularly potent because the software runs with elevated privileges and is designed for public access, creating a large attack surface. Organizations using Accellion FTA should prioritize migration to modern, actively maintained file-transfer solutions.
The case also demonstrates the value of network segmentation. Qualys' decision to place the FTA server in a segregated DMZ limited the breach's impact, preventing attacker lateral movement into core production systems. This architectural pattern offers a model for other organizations running legacy internet-facing applications.
Furthermore, the delayed disclosure — with confirmation coming months after the initial December 2020 breach — raises questions about incident reporting timelines. The involvement of Mandiant suggests Qualys is treating this as a serious investigation, potentially uncovering additional details about the attack's origin and scope.
BleepingComputer contacted Qualys before publication and was awaiting an official statement. The company's eventual disclosure provides clarity for customers and partners who may have interacted with the compromised support system during the breach window.
Research Notes
Source: BleepingComputer article (https://www.bleepingcomputer.com/news/security/cybersecurity-firm-qualys-is-the-latest-victim-of-accellion-hacks/)
Key verified facts:
- Qualys confirmed their Accellion FTA server was breached in December 2020 (Qualys security incident notice)
- The zero-day vulnerability in Accellion FTA allowed attackers to steal files stored on the server
- Clop ransomware gang has been extorting victims by posting stolen data on their ransomware data leak site
- Before Qualys, known victims extorted by Clop include: Transport for NSW, Singtel, Bombardier, Fugro, law firm Jones Day, science and technology company Danaher, and technical services company ABS Group
- The Accellion FTA device was located at fts-na.qualys.com, with the server IP assigned to Qualys
- Qualys had deployed the Accellion FTA server in a segregated DMZ environment, completely separate from systems that host and support Qualys products
- The server was used to transfer information as part of Qualys' customer support system
- Qualys has shut down the affected Accellion FTA servers and switched to alternative applications for support-related file transfers
- Qualys is still investigating the breach and has hired Mandiant to assist them
- BleepingComputer contacted Qualys before publication and are awaiting an official statement
- Qualys confirmed no impact on production environments, codebase, or customer data hosted on the Qualys Cloud Platform; all Qualys platforms continue to be fully functional with no operational impact at any time
Source
- Qualys is the latest victim of Accellion hacks exploiting a zero-day vulnerability
- The Accellion FTA server breach occurred in December 2020
- Clop ransomware gang is extorting victims by posting stolen data on their leak site
- Known prior victims include Transport for NSW, Singtel, Bombardier, Fugro, Jones Day, Danaher, and ABS Group
- Qualys confirmed the breach in a security incident notice today
- The Accellion FTA device was located at fts-na.qualys.com with IP assigned to Qualys
- Qualys deployed the server in a segregated DMZ environment separate from production systems
- Qualys has shut down the affected Accellion FTA servers and switched to alternative applications
- Qualys is still investigating the breach and has hired Mandiant to assist
- BleepingComputer contacted Qualys before publication and are awaiting an official statement