Reports have linked professional services firm Aon to the Termite ransomware group, which is said to have exploited a flaw in Cleo file-transfer software. The flaw is tracked as CVE-2024-50623. The story is still developing, and the details matter. Here is a plain account of the Aon Termite ransomware Cleo CVE-2024-50623 reports, what can be stated with confidence, and what teams that move sensitive files should do.
What Is Confirmed and What Is Only Claimed
The starting point is the source reporting: reports tie Aon to Termite ransomware activity that exploits the Cleo file-transfer vulnerability CVE-2024-50623. That is a link made by reports, not a finding we can independently verify.
One search result summary from a third-party analysis site says Aon was publicly reported as a ransomware victim on October 7, 2026. That is a secondary source's description, and we are attributing it rather than adopting it as established fact. The material available to us does not include a detailed statement from Aon, a technical breakdown of how any intrusion happened, or confirmation of what data, if any, was taken.
So the cautious reading looks like this:
- Established: CVE-2024-50623 is a real, documented vulnerability in Cleo software. Cleo published a security advisory about it on December 10, 2024.
- Reported, not verified here: that Aon was hit by Termite ransomware and that the Cleo flaw was the entry point.
- Unknown from the available material: the scope of any data exposure, whether customer or employee information was involved, and the timeline of any compromise.
Until the company or investigators publish more, treat attribution to a specific group and a specific vulnerability as an allegation.
How CVE-2024-50623 in Cleo Software Was Exploited
According to Cleo's own advisory, CVE-2024-50623 is an unrestricted file upload and download vulnerability that could lead to remote code execution. In everyday terms, a flaw like this can let an attacker place files on a server that should have rejected them, and then run code of their choosing on it. A file-transfer server often sits at the edge of a network and holds sensitive documents, so that is a powerful foothold.
Security vendors have tied the flaw to Cleo Harmony, VLTrader, and LexiCom. One analysis describes the Cl0p group exploiting CVE-2024-50623 and a related flaw, CVE-2024-55956, in those products. Another vendor writeup from January 2025 describes active exploitation of Cleo software in the wild, and a separate post noted that the flaws threatened large enterprises.
That history is why the Aon reports are notable. If Termite is now tied to the same vulnerability, it suggests a flaw that was publicly known and patchable has remained useful to more than one ransomware operation. We cannot say from the available material whether that holds here, but it is the question investigators will likely be asking.
What Organizations Running Cleo Should Check Now
You do not need to wait for the Aon story to settle before reviewing your own exposure. Teams that use Cleo Harmony, VLTrader, or LexiCom can work through a short list:
- Confirm patch status. Check Cleo's official security advisory for CVE-2024-50623 and verify that your installed versions match the fixed releases it describes. Do the same for CVE-2024-55956.
- Inventory your instances. Shadow or forgotten file-transfer servers, including test systems and those run by business units, are common gaps.
- Reduce exposure. Review whether the server needs to be reachable from the internet, and restrict access where it does not.
- Look for signs of compromise. Patching closes the door but does not remove an intruder who is already inside. Review logs, unexpected files, and unusual outbound transfers, and follow the guidance in vendor and incident-response advisories.
- Ask your suppliers. If a vendor or partner handles your files through Cleo software, ask them directly about patch status and whether they have assessed their exposure.
Why File-Transfer Tools Keep Attracting Ransomware Groups
Managed file-transfer software is an appealing target for a simple reason: it concentrates valuable data in one place and often connects many organizations at once. A single weakness can give an attacker access to documents from numerous companies, rather than one.
There is also a trust problem. Businesses exchange contracts, financial records, and personal data through these tools, often on the assumption that the vendor's software is hardened. When a flaw is found, customers depend on the vendor to disclose it and on their own teams to patch quickly. Delays at either step leave a window that criminals can use.
For privacy, the issue is that your information may sit in systems you never chose and cannot see. Employers, insurers, brokers, and service providers may all run third-party transfer tools that touch your data.
What This Means For You
If you are an individual, you cannot patch a company's file-transfer server, but you can limit the damage from any third-party exposure. Watch for official breach notifications and read them carefully. Be skeptical of unexpected messages that reference your accounts or employer, since stolen data is often used for phishing. Use unique passwords and multi-factor authentication, and consider credit monitoring if a notice says financial or identity details were involved.
A VPN does not protect against this type of incident. It encrypts your own traffic, but it does not stop a company's server from being compromised. Data stored with third parties depends on how those parties secure it.
If you manage IT or security at an organization, the lesson is more direct: file-transfer software deserves the same patch discipline as your firewall or email gateway.
Key Takeaways
- Treat the link between Aon, Termite ransomware, and Cleo as reported, not proven, until Aon or investigators provide details.
- CVE-2024-50623 is a documented Cleo flaw that Cleo addressed in an advisory dated December 10, 2024.
- If you run Cleo products, verify patch status against the official advisory, inventory your instances, and check for signs of prior compromise.
- If you handle sensitive data, ask vendors and partners about their file-transfer security and patching.
- Monitor official advisories from Cleo and your own security providers, and update this picture as verified details emerge on the Aon Termite ransomware Cleo CVE-2024-50623 reports.




