www.splunk.com Aon Hit by Ransomware Attack via Cleo CVE-2024 Exploit
Article Content
- •Aon was attacked by the Termite ransomware group on October 6, 2026.
- •The attack exploited CVE-2024-50623 in Cleo software, affecting even patched systems.
- •Termite's tactics include encrypting resources and deleting recovery options to maximize disruption.
On October 7, 2026, Aon was reported as a victim of a ransomware attack attributed to the Termite group. The breach was discovered on the same day, with the initial compromise occurring on October 6, 2026. Termite exploited CVE-2024-50623, an unauthenticated remote code execution vulnerability in Cleo file transfer products, including LexiCom, VLTransfer, and Harmony. Despite a patch being released, even systems updated to version 5.8.0.21 remain vulnerable. The attack allows the ransomware to encrypt local and remote resources and delete shadow copies, complicating recovery efforts. At this time, Aon has not released an official statement detailing the specific data compromised. This incident reflects the ongoing threat of ransomware targeting high-value organizations in various sectors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Termite, Termite Group and Aon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2024-50623?
Is Aon confirming the data compromised?
What should organizations using Cleo software do?
Continue Reading
Multiple Companies Targeted by Ransomware Groups MONEYMESSAGE and TERMITE On September 21 and 22, 2026, two ransomware groups, MONEYMESSAGE and TERMITE, claimed attacks on multiple companies. MONEYMESSAGE listed U.S. Electrical Services and Wiedenbach Brown, while TERMITE named Sealcon, TruAmerica Multifamily, and theLender as victims. The posts provided no details on the attack methods…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…