Back to the archive

The encyclopedia · Software & IT · Operational decision · 2023

The MOVEit breach hit 2,500 organizations — because one file transfer tool had a zero-day

In 2023, a zero-day in MOVEit Transfer software was exploited by the Cl0p ransomware gang. Over 2,500 organizations and 90M+ people were affected worldwide.

Progress Software · 2023-05

What happened

In May 2023, the Cl0p ransomware gang exploited a zero-day vulnerability in MOVEit Transfer, a managed file transfer software made by Progress Software. The vulnerability allowed the attackers to gain unauthorized access to MOVEit servers used by organizations worldwide.

The breach was massive in scope: over 2,500 organizations were affected, including government agencies, universities, healthcare providers and major corporations. Over 90 million people's personal data was compromised. The attack was a 'supply chain' breach: rather than hacking individual organizations, the attackers compromised the software they all used.

The MOVEit breach was the largest cyberattack of 2023 and one of the most consequential supply chain attacks in history, alongside SolarWinds. The case illustrated how a single vulnerability in a widely used infrastructure tool can compromise thousands of organizations simultaneously, and how the attack surface of the modern enterprise extends far beyond its own network to every vendor and tool it uses.

Why it happened

  • A zero-day in MOVEit Transfer was exploited by the Cl0p ransomware gang.
  • Over 2,500 organizations and 90M+ people were affected worldwide.
  • The attack was a supply chain breach: one tool compromised thousands of organizations.
  • The breach was the largest cyberattack of 2023.
What it cost2,500+ organizations; 90M+ people; global breachcatastrophic

The lesson

The modern enterprise's attack surface is every tool and vendor it uses. MOVEit was one tool; one zero-day compromised 2,500 organizations. Supply chain security is your problem.

Aftermath

Progress Software patched the vulnerability. The Cl0p gang was targeted by international law enforcement. The case prompted organizations to review their supply chain security and adopt zero-trust architectures for third-party tools.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →