The encyclopedia · Software & IT · Operational decision · 2023
The MOVEit breach hit 2,500 organizations — because one file transfer tool had a zero-day
In 2023, a zero-day in MOVEit Transfer software was exploited by the Cl0p ransomware gang. Over 2,500 organizations and 90M+ people were affected worldwide.
Progress Software · 2023-05
What happened
In May 2023, the Cl0p ransomware gang exploited a zero-day vulnerability in MOVEit Transfer, a managed file transfer software made by Progress Software. The vulnerability allowed the attackers to gain unauthorized access to MOVEit servers used by organizations worldwide.
The breach was massive in scope: over 2,500 organizations were affected, including government agencies, universities, healthcare providers and major corporations. Over 90 million people's personal data was compromised. The attack was a 'supply chain' breach: rather than hacking individual organizations, the attackers compromised the software they all used.
The MOVEit breach was the largest cyberattack of 2023 and one of the most consequential supply chain attacks in history, alongside SolarWinds. The case illustrated how a single vulnerability in a widely used infrastructure tool can compromise thousands of organizations simultaneously, and how the attack surface of the modern enterprise extends far beyond its own network to every vendor and tool it uses.
Why it happened
- A zero-day in MOVEit Transfer was exploited by the Cl0p ransomware gang.
- Over 2,500 organizations and 90M+ people were affected worldwide.
- The attack was a supply chain breach: one tool compromised thousands of organizations.
- The breach was the largest cyberattack of 2023.
The lesson
The modern enterprise's attack surface is every tool and vendor it uses. MOVEit was one tool; one zero-day compromised 2,500 organizations. Supply chain security is your problem.
Aftermath
Progress Software patched the vulnerability. The Cl0p gang was targeted by international law enforcement. The case prompted organizations to review their supply chain security and adopt zero-trust architectures for third-party tools.
Sources
- MOVEit data breach — Wikipedia
- CISA/FBI advisory AA23-158A, 7 June 2023 — #StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability (zero-day SQL injection in Progress Software's MOVEit Transfer)
spotted an error? The club wants to know.
More like this
Hackers hid in SolarWinds' update — 18,000 organizations installed the backdoor
Clearview AI scraped billions of faces and Europe fined it country by country
Azure Front Door outage takes down M365, Xbox and Azure Portal worldwide
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.