Don’t do SECURITY. Do business SECURELY.

Clop exploits MOVEit Transfer flaw in mass data theft campaign

A zero-day in Progress Software's MOVEit Transfer let the Clop gang steal data from thousands of organisations, including BBC, BA, and Boots.

Progress Software warned of a critical vulnerability in its MOVEit Transfer file transfer software that was already being exploited. The Clop extortion gang claimed responsibility for mass data theft using the flaw.

What happened

  • The SQL injection flaw, CVE-2023-34362, allowed attackers to access databases and steal files from internet-facing MOVEit servers.
  • UK payroll provider Zellis confirmed it had been affected, exposing staff data from clients including the BBC, British Airways, and Boots.
  • Victims later included government agencies, universities, and companies worldwide, with researchers counting more than 2,000 affected organisations.
  • Clop threatened to publish data on its leak site unless organisations contacted it to negotiate.

Why it mattered

MOVEit became one of the largest data theft campaigns on record and showed how a single vulnerability in a supplier’s software can expose data across whole supply chains. Clop stole data rather than encrypting systems, relying on the threat of publication alone.

Lessons for organisations

Organisations should know which suppliers hold their data and how, patch internet-facing file transfer systems urgently, and minimise how long files are kept on them. Contracts should require suppliers to notify customers promptly about incidents affecting their data.

Source: The Record

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights