Fluke Corporation Confirms 2025 Data Breach Impacting 18,517 Individuals
Fluke Corporation, a Washington-based manufacturer of industrial testing equipment, disclosed a data breach affecting 18,517 individuals after hackers exploited a vulnerability in a third-party application. The breach, which occurred between August 10 and October 7, 2025, exposed sensitive data, including Social Security numbers, dates of birth, and disability self-identification indicators. Fluke detected the intrusion on September 29, 2025, and has since notified affected parties, offering 24 months of free credit monitoring and identity theft insurance through Equifax.
The ransomware group Clop claimed responsibility for the attack, though Fluke has not confirmed the assertion. Clop, active since 2019, specializes in exploiting zero-day vulnerabilities in enterprise software, including recent attacks on Oracle’s E-Business Suite and file transfer applications. In 2025 alone, Clop took credit for 458 ransomware incidents, with 40 confirmed by targeted organizations. This year, the group has already claimed 122 additional attacks, including a breach at Tulane University affecting 4,633 individuals.
The Fluke breach aligns with a broader trend of ransomware attacks on U.S. manufacturers, which saw 92 confirmed incidents in 2025, compromising approximately 156,000 personal records. Other recent manufacturing breaches include attacks on Extant Aerospace (August 2025), Mill Creek Fabrics (September 2025), and AOTCO Metal Finishing (March 2026). Such attacks often disrupt operations, steal data, and demand ransoms to prevent public disclosure or further exploitation.
Source: https://www.comparitech.com/news/fluke-corp-notifies-18000-people-of-data-breach-that-leaked-ssns/
Fluke Corporation cybersecurity rating report: https://www.rankiteo.com/company/fluke-corporation
"id": "FLU1778869908",
"linkid": "fluke-corporation",
"type": "Ransomware",
"date": "8/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '18,517',
'industry': 'Industrial testing equipment '
'manufacturing',
'location': 'Washington, USA',
'name': 'Fluke Corporation',
'type': 'Corporation'}],
'attack_vector': 'Exploitation of third-party application vulnerability',
'customer_advisories': '24 months of free credit monitoring and identity '
'theft insurance through Equifax',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '18,517',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Social Security numbers',
'Dates of birth',
'Disability self-identification '
'indicators']},
'date_detected': '2025-09-29',
'date_publicly_disclosed': '2025-10-07',
'description': 'Fluke Corporation disclosed a data breach affecting 18,517 '
'individuals after hackers exploited a vulnerability in a '
'third-party application. The breach exposed sensitive data, '
'including Social Security numbers, dates of birth, and '
'disability self-identification indicators. The ransomware '
'group Clop claimed responsibility for the attack.',
'impact': {'data_compromised': 'Social Security numbers, dates of birth, '
'disability self-identification indicators',
'identity_theft_risk': 'High',
'operational_impact': 'Disruption of operations'},
'initial_access_broker': {'entry_point': 'Third-party application '
'vulnerability'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain, Data exfiltration',
'post_incident_analysis': {'root_causes': 'Exploitation of zero-day '
'vulnerability in third-party '
'application'},
'ransomware': {'data_exfiltration': 'Yes', 'ransomware_strain': 'Clop'},
'references': [{'source': 'Fluke Corporation Disclosure'}],
'response': {'communication_strategy': 'Notification to affected parties',
'third_party_assistance': 'Equifax (credit monitoring and '
'identity theft insurance)'},
'threat_actor': 'Clop',
'title': 'Fluke Corporation Data Breach Impacting 18,517 Individuals',
'type': 'Data Breach, Ransomware',
'vulnerability_exploited': 'Zero-day vulnerability in enterprise software'}