← Case Files · The Breach Files
MOVEit, 2023: one file transfer product, 2,700 organisations
- People affected
- over 2,700 organisations; more than 90 million individuals
- When it happened
- 27 May 2023 onwards
- Made public
- 31 May 2023
- How they got in
- A SQL injection zero-day (CVE-2023-34362) in Progress MOVEit Transfer
- Attributed to
- The Cl0p ransomware group
- What it cost
- Estimated in the billions across all victims; a US reward of up to $10 million was offered for information
What was exposed: Names · Addresses · Dates of birth · Social Security and national ID numbers · Payroll and pension data · Health data, depending on the victim organisation
Over the US Memorial Day weekend in 2023, one criminal group stole data from thousands of organisations simultaneously. They did not attack those organisations. They attacked a single piece of software that all of them used to move sensitive files, and let the product's own customer base do the rest.
What happened
MOVEit Transfer, made by Progress Software, is managed file transfer software. Organisations use it to send large, sensitive files to partners with encryption and an audit trail: payroll data to a bureau, claims files to an insurer, citizen records between agencies. Its whole purpose is to be trusted with the things that matter.
On 27 May 2023, attackers began exploiting a zero-day SQL injection vulnerability — later designated CVE-2023-34362 — in the product's web interface. No credentials were required. The flaw allowed database commands to be executed and a web shell to be planted, after which the attacker could inventory and download whatever files the instance held.
Progress published an advisory and a patch on 31 May. By then Cl0p had been harvesting for days, and the pattern of the campaign made clear it had been prepared in advance: scripted, automated, and launched into a holiday weekend when incident response teams were thin.
Why file transfer products specifically. This was not Cl0p's first time. The group exploited Accellion FTA in 2021 and Fortra GoAnywhere in early 2023, and similar products have been targeted since. The logic is exact: managed file transfer servers are internet-facing by design, they hold concentrated sensitive data by design, and they sit at the boundary between organisations, so one compromise yields data belonging to many parties. It is the highest-leverage target class in enterprise software.
The blast radius
Trackers counted more than 2,700 affected organisations and over 90 million individuals. The composition is the point:
- Through a payroll provider — employees of the BBC, British Airways and Boots, none of whom had any relationship with MOVEit.
- Through US state agencies — millions of drivers' records from motor vehicle departments in Oregon and Louisiana.
- Through government contractors — Maximus, which administers health and human services programmes, reported around 11 million individuals.
- Through insurers, universities, pension administrators and benefits processors, in numbers that continued to be disclosed for more than a year afterwards.
Very few of the people in that data had ever made a decision that led to it. That is the defining feature of supply-chain breaches: consent and exposure are completely decoupled.
Extortion without encryption
Cl0p did not encrypt systems. It took data and threatened publication, listing victims on its leak site with countdowns and releasing files for those who refused.
This shift — from ransomware to pure data extortion — is now the dominant model, and the reasons are practical. Encryption is noisy, triggers alarms, and can be defeated by good backups. Exfiltration is quiet, and backups are no defence against publication. For the victim, the calculation changes completely: you can restore your systems perfectly and still be facing the same demand.
The timeline
- 27 May 2023 — Mass exploitation of the zero-day begins over the holiday weekend.
- 31 May 2023 — Progress publishes an advisory and patch; CVE-2023-34362 is assigned.
- June 2023 — Cl0p claims responsibility and begins naming victims; CISA and the FBI publish a joint advisory; the US offers a reward of up to $10 million for information.
- June–July 2023 — Further vulnerabilities are found and patched in the same product as researchers audit it.
- 2023–2024 — Victim disclosures continue in a long tail, as organisations work out whose data was in their instances.
What it changed
Fourth-party risk became a real concept. Organisations had begun mapping their suppliers. MOVEit forced the next question: which software do our suppliers depend on, and would we even know if it failed? Many victims learned they were affected only when a vendor's vendor notified them.
Managed file transfer got treated as critical infrastructure. Security teams inventoried these products, moved them behind access controls rather than exposing them to the internet, and started deleting the files that had accumulated in them. A transfer product holding four years of completed transfers is a warehouse pretending to be a pipe.
Holiday-weekend readiness stopped being a joke. The timing was deliberate and it has been deliberate in every major campaign since. Coverage planning for long weekends is now an explicit part of incident response planning.
If you were notified
- Read which organisation notified you, not which software failed. Your exposure depends entirely on what that particular body held about you.
- Freeze your credit if national identifiers were involved. Payroll and benefits files are unusually complete: name, address, date of birth, national ID and salary in one row.
- Expect a long tail. Notifications for this event continued for well over a year; a letter arriving late does not mean it is a scam, but verify it through the organisation's own published contact details rather than the letter's.
- If you run MOVEit or similar software, delete completed transfers on a schedule. The single control that most reduced damage among victims was simply not having old files still sitting there.
Questions people ask
What is MOVEit and why did so many organisations use it?
MOVEit Transfer is managed file transfer software: the tool an organisation uses to move large, sensitive files to partners with an audit trail — payroll to a bureau, claims to an insurer, records to a government agency. It is used precisely because the files are sensitive, which is what made compromising it so effective.
How did the attack work?
A previously unknown SQL injection flaw in the MOVEit web interface, tracked as CVE-2023-34362, allowed unauthenticated attackers to run database commands and deploy a web shell. From there they listed and downloaded whatever the instance held. Exploitation began over a holiday weekend, when fewer defenders were watching.
Why were people affected who had never used MOVEit?
Because their employer, pension provider, insurer or government agency used it, or used a supplier that did. The British Broadcasting Corporation, British Airways and Boots employees were exposed through a payroll provider. Millions of US drivers were exposed through state motor vehicle agencies. You cannot opt out of software you were never told about.
Was this ransomware?
Not in the encrypting sense. Cl0p did not lock systems — it stole data and demanded payment to keep it unpublished, listing non-paying victims on its leak site. That shift from encryption to pure extortion has continued, because stealing is faster, quieter and harder to recover from with backups.
Sources
- Progress Software security advisories for MOVEit Transfer, May–June 2023
- CISA and FBI joint advisory AA23-158A on Cl0p exploitation of MOVEit
- US Department of State, Rewards for Justice — Cl0p reward announcement, June 2023
- Emsisoft, running tally of MOVEit victims and affected individuals, 2023–2024
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.