Skip to content
Aon Hit by Ransomware Attack via Cleo CVE-2024 Exploit

Aon Hit by Ransomware Attack via Cleo CVE-2024 Exploit

First seen 7 Oct 2026, 10:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 10:57 UTC
  • •Aon was attacked by the Termite ransomware group on October 6, 2026.
  • •The attack exploited CVE-2024-50623 in Cleo software, affecting even patched systems.
  • •Termite's tactics include encrypting resources and deleting recovery options to maximize disruption.

On October 7, 2026, Aon was reported as a victim of a ransomware attack attributed to the Termite group. The breach was discovered on the same day, with the initial compromise occurring on October 6, 2026. Termite exploited CVE-2024-50623, an unauthenticated remote code execution vulnerability in Cleo file transfer products, including LexiCom, VLTransfer, and Harmony. Despite a patch being released, even systems updated to version 5.8.0.21 remain vulnerable. The attack allows the ransomware to encrypt local and remote resources and delete shadow copies, complicating recovery efforts. At this time, Aon has not released an official statement detailing the specific data compromised. This incident reflects the ongoing threat of ransomware targeting high-value organizations in various sectors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-10-27
CVE-2024-50623 published
CVE-2024-50623, a critical RCE vulnerability in Cleo software, was published.
Splunk
2024-12-13
CVE-2024-50623 added to CISA KEV
CISA added CVE-2024-50623 to the Known Exploited Vulnerabilities catalog due to active exploitation.
Splunk
2026-10-07
Aon ransomware attack disclosed
Aon was reported as a victim of a ransomware attack attributed to the Termite group, with the breach discovered on the same day.
Rescana

More articles in this cluster (2)

Following this threat?

Track Termite, Termite Group and Aon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2024-50623?
CVE-2024-50623 is a critical unauthenticated remote code execution vulnerability in Cleo's file transfer products.
Is Aon confirming the data compromised?
No official statement from Aon has been released detailing the specific data compromised.
What should organizations using Cleo software do?
Organizations should ensure they apply the latest patches and monitor for signs of exploitation.