Progress Software warned of a critical vulnerability in its MOVEit Transfer file transfer software that was already being exploited. The Clop extortion gang claimed responsibility for mass data theft using the flaw.
What happened
- The SQL injection flaw, CVE-2023-34362, allowed attackers to access databases and steal files from internet-facing MOVEit servers.
- UK payroll provider Zellis confirmed it had been affected, exposing staff data from clients including the BBC, British Airways, and Boots.
- Victims later included government agencies, universities, and companies worldwide, with researchers counting more than 2,000 affected organisations.
- Clop threatened to publish data on its leak site unless organisations contacted it to negotiate.
Why it mattered
MOVEit became one of the largest data theft campaigns on record and showed how a single vulnerability in a supplier’s software can expose data across whole supply chains. Clop stole data rather than encrypting systems, relying on the threat of publication alone.
Lessons for organisations
Organisations should know which suppliers hold their data and how, patch internet-facing file transfer systems urgently, and minimise how long files are kept on them. Contracts should require suppliers to notify customers promptly about incidents affecting their data.
Source: The Record
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.