By J. Mesa
In late May 2023, a criminal group began stealing files from organizations around the world through a single piece of software. The software was MOVEit Transfer, and the attack became one of the largest data theft events on record.
I first wrote about it in our June 2023 Cyber Bytes. This post is the full explanation: what happened, who was affected, and what a small business can learn from it.
What is MOVEit?
MOVEit Transfer is a managed file transfer product made by Progress Software. Organizations use it to send large or sensitive files in a secure way, such as payroll data, health records, and financial reports. Banks, governments, universities, and the vendors that serve them relied on it.
That is the reason the breach spread so far. The product existed to move the most sensitive files an organization had.
What happened in the MOVEit breach?
Attackers found a flaw in MOVEit Transfer that the vendor did not yet know about. A flaw like that is called a zero-day, because the vendor has had zero days to fix it.
The flaw is tracked as CVE-2023-34362. It was a SQL injection vulnerability, which means an attacker could send crafted input to the application and make its database run the attacker’s commands. Through it, the attackers installed a hidden backdoor on MOVEit servers and downloaded the stored files.
Progress Software disclosed the flaw and released a fix on May 31, 2023. By then the attackers had already been at work for days.
Who was behind the attack?
A ransomware group known as Clop, also written Cl0p, claimed responsibility. In this campaign the group did not encrypt its victims’ files. It stole the data and then threatened to publish it unless each victim paid.
Security teams call this data extortion. It works on organizations that have good backups, because a backup does not undo a leak.
How many organizations were affected?
Researchers who tracked the campaign counted more than 2,500 organizations and tens of millions of individuals. The victims included government agencies, banks, universities, healthcare providers, and large employers.
Many of them never ran MOVEit. Their payroll provider, pension administrator, or other vendor did. The attackers reached those organizations’ data through a supplier.
Was my data exposed in the MOVEit breach?
If it was, the affected organization should have sent you a notice. You can also:
- Search your email address at haveibeenpwned.com
- Review letters from your employer, bank, health plan, or state agencies from 2023 and 2024
- Take up any free credit monitoring those notices offered
If your data was exposed, place a free credit freeze with Equifax, Experian, and TransUnion, and treat unexpected messages about your accounts with suspicion.
Why did the attack spread so fast?
- The software faced the internet. MOVEit servers accept connections from outside, so attackers could reach them directly.
- Nobody had a patch. A zero-day leaves defenders with no fix until the vendor releases one.
- The attackers prepared. They struck many servers in a short window, before word spread.
- The data was concentrated. One server held files from many clients.
What is a supply chain attack?
A supply chain attack reaches you through a company you trust. You hand your data to a vendor, and the attacker breaks into the vendor.
MOVEit showed how far that reaches. Your security depends on your own controls and on the controls of every company that holds your data.
What should a business do after an incident like this?
- Find out if you run the affected product. Check your own systems, then ask your vendors.
- Apply the vendor’s fix right away. If you can’t, take the system offline until you can.
- Look for signs of intrusion. Follow the vendor’s guidance on what to check.
- Reset credentials that the system stored or used.
- Notify affected people as the law requires.
What does MOVEit teach a small business?
- Patch fast. Install security updates as soon as vendors release them, and start with anything that faces the internet.
- Know your vendors. Keep a list of who holds your data and what they hold. Ask each one how they protect it and how they will tell you about a breach.
- Limit what you share and store. Send vendors only the data they need. Delete files from transfer systems once they have arrived.
- Control access. Use multi-factor authentication and give each account the least access it needs.
- Train your people. After a breach, criminals send phishing emails that use the stolen details. Staff who expect that are harder to fool.
- Plan your response. Decide now who you will call and how you will notify customers.
What questions should I ask my vendors?
- Which of our data do you store, and for how long?
- How fast do you install security updates?
- Do you require multi-factor authentication for your staff?
- How will you notify us of a breach, and within what time?
- Do you have an independent security report, such as a SOC 2?
A vendor who answers these without hesitation takes security seriously. One who can’t answer has told you something too.
Could this happen again?
Yes. Attackers have hit other file transfer products with the same playbook before and since. Any widely used tool that holds sensitive data and faces the internet is a target. You can’t prevent a zero-day. You can limit what an attacker finds, and you can respond fast.
Does good backup protect me from data extortion?
No. Backups protect you from losing access to your files. They do nothing once an attacker holds a copy. The defenses against data theft are different: store less, encrypt sensitive files, restrict who and what can reach them, and watch for large transfers leaving your network. Plan for both kinds of attack, because criminal groups now use both.
Should a victim pay the ransom?
The FBI advises against paying. Payment does not guarantee the criminals delete the data, and it funds the next attack. Each case carries legal and business questions, so involve your attorney, your insurer, and law enforcement before you decide.
Your next step
Make a list of every vendor that holds your customer or employee data. If the list surprises you, that is useful to know. Cerberus Cybersecurity helps businesses review vendor risk as part of our risk and compliance assessments. Contact us to get started.

Leave a Reply