From Wikipedia, the free encyclopedia

Series of cyberattacks exploiting vulnerability in Progress Software's software

2023 MOVEit data breach

|  |  |
| --- | --- |
| Type | [Cyberattack](/wiki/Cyberattack), [data breach](/wiki/Data_breach) |
| Cause | [MOVEit](/wiki/MOVEit) vulnerabilities |
| First reporter | [Progress Software](/wiki/Progress_Software) |
| Suspects | [Cl0p](/wiki/Clop_(cyber_gang)) |

Discovered in May 2023, a critical vulnerability in the [MOVEit](/wiki/MOVEit) [managed file transfer](/wiki/Managed_file_transfer) software triggered a wave of [cyberattacks](/wiki/Cyberattack) and [data breaches](/wiki/Data_breach).[[1]](#cite_note-:0-1) Exploited by the notorious ransomware group [CL0P](/wiki/Clop_(cyber_gang)), the flaw enabled unauthorized access to sensitive [databases](/wiki/Database), leading to the compromise of over 2,700 organizations and exposing the personal data of approximately 93.3 million individuals.[[2]](#cite_note-2) The breach had far-reaching effects across sectors like healthcare, finance, and government, emphasizing the systemic risks inherent in the interconnected nature of the [digital supply chain](/wiki/Digital_supply_chain).[[3]](#cite_note-:1-3)

## Background

[[edit](/w/index.php?title=2023_MOVEit_data_breach&action=edit&section=1)]

[MOVEit](/wiki/MOVEit), a managed file transfer software developed by [Ipswitch, Inc](/wiki/Ipswitch,_Inc.)., a subsidiary of [Progress Software](/wiki/Progress_Software), is widely used for securely transmitting large volumes of sensitive data across various industries, including government and highly regulated sectors.[[1]](#cite_note-:0-1) On May 28, 2023, a vulnerability in the MOVEit software was reported following unusual activity detected by a customer.[[1]](#cite_note-:0-1) This [zero-day vulnerability](/wiki/Zero-day_vulnerability) enabled attackers to exploit public-facing servers via [SQL injection](/wiki/SQL_injection), facilitating unauthorized file theft.[[3]](#cite_note-:1-3) The attacks were conducted using a custom web shell, known as LEMURLOOT, which impersonates legitimate ASP.NET files and can extract Microsoft Azure Storage Blob data.[[4]](#cite_note-:2-4)

## Timeline

[[edit](/w/index.php?title=2023_MOVEit_data_breach&action=edit&section=2)]

According to cybersecurity firm [Mandiant](/wiki/Mandiant), the MOVEit vulnerability began being used on May 27, 2023.[[5]](#cite_note-ArsInfo-5)

On May 31 Progress Software released a patch for the vulnerability and stated the vulnerability “could lead to escalated privileges and potential unauthorized access to the environment”.[[1]](#cite_note-:0-1)

On June 3, the [Government of Nova Scotia](/wiki/Government_of_Nova_Scotia) estimated that as many as 100,000 present and past employees were impacted by the breach.[[6]](#cite_note-6)

On June 5, various organizations in the United Kingdom, including the [BBC](/wiki/BBC), [British Airways](/wiki/British_Airways), [Boots](/wiki/Boots_(company)), [Aer Lingus](/wiki/Aer_Lingus), and payroll service Zellis were breached.[[4]](#cite_note-:2-4)

On June 6, Cl0p claimed responsibility for the attack on its site on the dark web. Cl0p claimed that the data stole from governments had been deleted (this was later disproved).[[1]](#cite_note-:0-1)

On June 12, [Ernst & Young](/wiki/Ernst_%26_Young), [Transport for London](/wiki/Transport_for_London), and [Ofcom](/wiki/Ofcom) separately announced that they had been affected, with Ofcom announcing that personal and confidential information was downloaded.[[7]](#cite_note-7)

On June 15, [CNN](/wiki/CNN) reported that the [United States Department of Energy](/wiki/United_States_Department_of_Energy) was among multiple United States government organizations affected by the MOVEit vulnerability.[[8]](#cite_note-8) The following day, it was reported that the [Louisiana](/wiki/Louisiana) Office of Motor Vehicles and [Oregon](/wiki/Oregon) Driver and Motor Vehicle Services were hit, affecting millions of residents.[[9]](#cite_note-9)

## Responsibility

[[edit](/w/index.php?title=2023_MOVEit_data_breach&action=edit&section=3)]

According to the [Cybersecurity and Infrastructure Security Agency](/wiki/Cybersecurity_and_Infrastructure_Security_Agency) and the [Federal Bureau of Investigation](/wiki/Federal_Bureau_of_Investigation), the breaches are being conducted by [Cl0p](/wiki/Clop_(cyber_gang)), a Russian-affiliated cyber gang.[[10]](#cite_note-10)

## Impact

[[edit](/w/index.php?title=2023_MOVEit_data_breach&action=edit&section=4)]

A running total maintained by cybersecurity company [Emsisoft](/wiki/Emsisoft) showed that more than 2,500 organizations were known to have been impacted as at October 25, 2023, with more than 80 percent of those organizations being US-based.[[11]](#cite_note-11)

## Response

[[edit](/w/index.php?title=2023_MOVEit_data_breach&action=edit&section=5)]

[Cybersecurity and Infrastructure Security Agency](/wiki/Cybersecurity_and_Infrastructure_Security_Agency) (CISA),[[12]](#cite_note-12) [CrowdStrike](/wiki/CrowdStrike),[[13]](#cite_note-13) [Mandiant](/wiki/Mandiant),[[14]](#cite_note-14) [Microsoft](/wiki/Microsoft),[[15]](#cite_note-15) Huntress[[16]](#cite_note-16) and Rapid7[[17]](#cite_note-17) have assisted with incident response and ongoing investigations.[[18]](#cite_note-18) Cyber industry experts have credited the [MOVEit](/wiki/MOVEit) team for its response and handling of the incident by quickly providing patches[[19]](#cite_note-19)[[20]](#cite_note-20) In general, patches for the flaw were rapidly used.[[21]](#cite_note-21)

## References

[[edit](/w/index.php?title=2023_MOVEit_data_breach&action=edit&section=6)]

1. ^ [***a***](#cite_ref-:0_1-0) [***b***](#cite_ref-:0_1-1) [***c***](#cite_ref-:0_1-2) [***d***](#cite_ref-:0_1-3) [***e***](#cite_ref-:0_1-4) Simas, Zach (July 18, 2023). ["Unpacking the MOVEit Breach: Statistics and Analysis"](https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/). *Emsisoft | Cybersecurity Blog*. Retrieved November 27, 2024.
2. **[^](#cite_ref-2)** Kapko, M.; Himmel, J. (January 16, 2024). ["Progress Software's Moveit Melt-down: Uncovering The Fallout"](https://www.cybersecuritydive.com/news/progress-software-moveit-meltdown/703659/). *Cybersecurity Dive*. Retrieved March 30, 2025.
3. ^ [***a***](#cite_ref-:1_3-0) [***b***](#cite_ref-:1_3-1) Kapko, M. (August 9, 2023). ["The Moveit Spree Is As Bad As — Or Worse Than — You Think It Is"](https://www.cybersecuritydive.com/news/moveit-attacks-bad-to-worse/690267/). *Cybersecurity Dive*.
4. ^ [***a***](#cite_ref-:2_4-0) [***b***](#cite_ref-:2_4-1) Tidy, Joe (June 5, 2023). ["MOVEit hack: BBC, BA and Boots among cyber attack victims"](https://www.bbc.com/news/technology-65814104). [BBC](/wiki/BBC). Retrieved June 15, 2023.
5. **[^](#cite_ref-ArsInfo_5-0)** Goodin, Dan (June 5, 2023). ["Mass exploitation of critical MOVEit flaw is ransacking orgs big and small"](https://arstechnica.com/information-technology/2023/06/mass-exploitation-of-critical-moveit-flaw-is-ransacking-orgs-big-and-small/). *[Ars Technica](/wiki/Ars_Technica)*. Retrieved June 15, 2023.
6. **[^](#cite_ref-6)** ["Privacy breach alerts and information"](https://novascotia.ca/privacy-breach/). *Nova Scotia Cyber Security and Digital Solutions*. June 4, 2023. Retrieved June 25, 2023.
7. **[^](#cite_ref-7)** Vallance, Chris (June 12, 2023). ["MOVEit hack: Media watchdog Ofcom latest victim of mass hack"](https://www.bbc.com/news/technology-65877210). [BBC](/wiki/BBC). Retrieved June 15, 2023.
8. **[^](#cite_ref-8)** Lyngaas, Sean (June 15, 2023). ["US government agencies hit in global cyberattack"](https://www.cnn.com/2023/06/15/politics/us-government-hit-cybeattack/index.html). [CNN](/wiki/CNN). Retrieved June 15, 2023.
9. **[^](#cite_ref-9)** Lyngaas, Sean (June 16, 2023). ["Millions of Americans' personal data exposed in global hack"](https://www.cnn.com/2023/06/16/politics/cyberattack-us-government/index.html). [CNN](/wiki/CNN). Retrieved June 15, 2023.
10. **[^](#cite_ref-10)** Montague, Zach (June 15, 2023). ["Russian Ransomware Group Breached Federal Agencies in Cyberattack"](https://www.nytimes.com/2023/06/15/us/politics/russian-ransomware-cyberattack-clop-moveit.html). *[The New York Times](/wiki/The_New_York_Times)*. Retrieved June 15, 2023.
11. **[^](#cite_ref-11)** *[Unpacking the MOVEit Breach: Statistics and Analysis](https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/)*,
12. **[^](#cite_ref-12)** ["#StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability"](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a). June 7, 2023. Retrieved June 7, 2023.
13. **[^](#cite_ref-13)** Lioi, Tyler; Palka, Sean (June 5, 2023). ["Movin' Out: Identifying Data Exfiltration in MOVEit Transfer Investigations"](https://www.crowdstrike.com/blog/identifying-data-exfiltration-in-moveit-transfer-investigations/). Retrieved June 5, 2023.
14. **[^](#cite_ref-14)** Zaveri, Nader; Kennelly, Jeremy; Stark, Genevieve (June 2, 2023). ["Zero-Day Vulnerability in MOVEit Transfer Exploited for Data Theft"](https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft). Retrieved June 2, 2023.
15. **[^](#cite_ref-15)** ["@MsftSecIntel"](https://twitter.com/MsftSecIntel/status/1665537730946670595). June 4, 2023. Retrieved June 4, 2023.
16. **[^](#cite_ref-16)** Hammond, John (June 1, 2023). ["MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response"](https://www.huntress.com/blog/moveit-transfer-critical-vulnerability-rapid-response). Retrieved June 1, 2023.
17. **[^](#cite_ref-17)** Condon, Caitlyn (June 1, 2023). ["Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability"](https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/). Retrieved June 1, 2023.
18. **[^](#cite_ref-18)** Kapko, Matt (June 14, 2023). ["MOVEit mass exploit timeline: How the file-transfer service attacks entangled victims"](https://www.cybersecuritydive.com/news/moveit-breach-timeline/687417/). Retrieved June 26, 2023.
19. **[^](#cite_ref-19)** Starks, Tim (June 7, 2023). ["Cyberdefenders respond to hack of file-transfer tool"](https://www.washingtonpost.com/politics/2023/06/07/cyberdefenders-respond-hack-file-transfer-tool/). *[The Washington Post](/wiki/The_Washington_Post)*. Retrieved June 7, 2023.
20. **[^](#cite_ref-20)** ["Inside the MOVEit Attack: Decrypting Clop's TTPs and Empowering Cybersecurity Practitioners"](https://www.infosecurity-magazine.com/podcasts/infosec-mag-pod-july-2023//). July 4, 2023. Retrieved July 4, 2023.
21. **[^](#cite_ref-21)** Stone, Noah (July 20, 2023). ["New research reveals rapid remediation of MOVEit Transfer vulnerabilities"](https://www.bitsight.com/blog/new-research-reveals-rapid-remediation-moveit-transfer-vulnerabilities/). [BitSight](/wiki/BitSight). Retrieved July 20, 2023.

| * [v](/wiki/Template:Hacking_in_the_2020s) * [t](/wiki/Template_talk:Hacking_in_the_2020s) * [e](/wiki/Special:EditPage/Template:Hacking_in_the_2020s)  Hacking in the 2020s |
| --- |
| ← [2010s](/wiki/Template:Hacking_in_the_2010s)  [Timeline](/wiki/List_of_security_hacking_incidents#2020s)  2030s → |
| Major incidents | |  |  | | --- | --- | | 2020 | * [BlueLeaks](/wiki/BlueLeaks) * [Twitter account hijacking](/wiki/2020_Twitter_account_hijacking) * [European Medicines Agency data breach](/wiki/European_Medicines_Agency_data_breach) * [Nintendo data leak](/wiki/Nintendo_data_leak) * [United States federal government data breach](/wiki/2020_United_States_federal_government_data_breach) * [EasyJet data breach](/wiki/EasyJet_data_breach) * [Vastaamo data breach](/wiki/Vastaamo_data_breach) | | 2021 | * [Microsoft Exchange Server breach](/wiki/2021_Microsoft_Exchange_Server_data_breach) * [Ivanti Pulse Connect Secure data breach](/wiki/Ivanti_Pulse_Connect_Secure_data_breach) * [Colonial Pipeline ransomware attack](/wiki/Colonial_Pipeline_ransomware_attack) * [Health Service Executive ransomware attack](/wiki/Health_Service_Executive_ransomware_attack) * [Waikato District Health Board ransomware attack](/wiki/Waikato_District_Health_Board_ransomware_attack) * [JBS S.A. ransomware attack](/wiki/JBS_S.A._ransomware_attack) * [Kaseya VSA ransomware attack](/wiki/Kaseya_VSA_ransomware_attack) * [Transnet ransomware attack](/wiki/Transnet_ransomware_attack) * [Epik data breach](/wiki/2021_Epik_data_breach) * [FBI email hack](/wiki/2021_FBI_email_hack) * [National Rifle Association ransomware attack](/wiki/2021_National_Rifle_Association_ransomware_attack) * [Banco de Oro hack](/wiki/2021_Banco_de_Oro_hack) * [Iranian fuel cyberattack](/wiki/2021_Iranian_fuel_cyberattack) | | 2022 | * [Ukraine cyberattacks](/wiki/2022_Ukraine_cyberattacks) * [Red Cross data breach](/wiki/Red_Cross_data_breach) * [Anonymous and the Russian invasion of Ukraine](/wiki/Anonymous_and_the_Russian_invasion_of_Ukraine) * [Viasat hack](/wiki/Viasat_hack) * [DDoS attacks on Romania](/wiki/2022_DDoS_attacks_on_Romania) * [Costa Rican ransomware attack](/wiki/2022_Costa_Rican_ransomware_attack) * [LastPass vault theft](/wiki/LastPass_2022_data_breach) * [Shanghai police database leak](/wiki/Shanghai_police_database_leak) * [*Grand Theft Auto VI* content leak](/wiki/Grand_Theft_Auto_VI#Leaks) | | 2023 | * [Munster Technological University ransomware attack](/wiki/Munster_Technological_University_ransomware_attack) * [Capita data breach](/wiki/2023_Capita_data_breach) * [Evide data breach](/wiki/Evide_data_breach) * MOVEit data breach * [Insomniac Games data breach](/wiki/Insomniac_Games#December_2023_leak) * [Operation Triangulation cyberattack](/wiki/Operation_Triangulation) * [Polish railway cyberattack](/wiki/Polish_railway_cyberattack) * [British Library cyberattack](/wiki/British_Library_cyberattack) | | 2024 | * [XZ Utils backdoor](/wiki/XZ_Utils_backdoor) * [Kadokawa and Niconico](/wiki/2024_cyberattack_on_Kadokawa_and_Niconico) * [Change Healthcare ransomware attack](/wiki/2024_Change_Healthcare_ransomware_attack) * [Ukrainian cyberattacks against Russia](/wiki/2024_Ukrainian_cyberattacks_against_Russia) * [2024 WazirX hack](/wiki/2024_WazirX_hack) * [Trump campaign hack](/wiki/Iranian_interference_in_the_2024_United_States_elections) * [Fur Affinity domain hijacking](/wiki/Fur_Affinity) * [IRLeaks attack on Iranian banks](/wiki/IRLeaks_attack_on_Iranian_banks) * [Internet Archive data breach](/wiki/Internet_Archive#2024_Cyberattacks) * [i-Soon leak](/wiki/I-Soon_leak) * [2024 global telecommunications hack](/wiki/2024_global_telecommunications_hack) * [2024 National Public Data breach](/wiki/2024_National_Public_Data_breach) | | 2025 | * [Cyberattacks on Bank Sepah](/wiki/Cyberattacks_on_Bank_Sepah) * [2025 Paraguay ransomware attack](/wiki/2025_Paraguay_ransomware_attack) * [4chan hacking and data breach](/wiki/4chan#2020s) * [2025 St. Paul cyberattack](/wiki/2025_St._Paul_cyberattack) * [Jaguar Land Rover cyberattack](/wiki/Jaguar_Land_Rover_cyberattack) * [Collins Aerospace cyberattack](/wiki/Collins_Aerospace_cyberattack) * [2025 cyberattack on Polish power grid](/wiki/2025_cyberattack_on_Polish_power_grid) | | 2026 | * [ManageMyHealth data breach](/wiki/ManageMyHealth_data_breach) * [Neighbourly data breach](/wiki/Neighbourly#Data_breach) | |
| Groups | * [Anonymous](/wiki/Anonymous_(hacker_group))   + [associated events](/wiki/Timeline_of_events_associated_with_Anonymous) * [Anonymous Sudan](/wiki/Anonymous_Sudan) * [Berserk Bear](/wiki/Berserk_Bear) * [BlackCat](/wiki/BlackCat_(cyber_gang)) * [Clop](/wiki/Clop_(cyber_gang)) * [Cozy Bear](/wiki/Cozy_Bear) * [DarkMatter](/wiki/DarkMatter_Group) * [DarkSide](/wiki/DarkSide_(hacker_group)) * [Dark Storm Team](/wiki/Dark_Storm_Team) * [Dridex](/wiki/Dridex) * [Ghostwriter](/wiki/Ghostwriter_(hacker_group)) * [GnosticPlayers](/wiki/GnosticPlayers) * [Guacamaya](/wiki/Guacamaya_(hacktivist_group)) * [Hacktivist Nepal](/wiki/Hacktivist_Nepal) * [Hafnium](/wiki/Hafnium_(group)) * [Indian Cyber Force](/wiki/Indian_Cyber_Force) * [IT Army of Ukraine](/wiki/IT_Army_of_Ukraine) * [Killnet](/wiki/Killnet) * [Lapsus$](/wiki/Lapsus$) * [LightBasin](/wiki/LightBasin) * [LockBit](/wiki/LockBit) * [OceanLotus](/wiki/OceanLotus) * [REvil](/wiki/REvil) * [Rhysida](/wiki/Rhysida_(hacker_group)) * [Sandworm](/wiki/Sandworm_(hacker_group)) * [Sakura Samurai](/wiki/Sakura_Samurai_(group)) * [ShinyHunters](/wiki/ShinyHunters) * [SiegedSec](/wiki/SiegedSec) * [Vice Society](/wiki/Vice_Society) * [Wizard Spider](/wiki/Wizard_Spider) |
| [Individuals](/wiki/Hacker) | * [Graham Ivan Clark](/wiki/Graham_Ivan_Clark) * [maia arson crimew](/wiki/Maia_arson_crimew) * [IntelBroker](/wiki/IntelBroker) * [Kirtaner](/wiki/Aubrey_Cottle) |
| Major [vulnerabilities](/wiki/Vulnerability_(computing)) publicly [disclosed](/wiki/Full_disclosure_(computer_security)) | * [SMBGhost](/wiki/SMBGhost) (2020) * [Thunderspy](/wiki/Thunderspy) (2020) * [PrintNightmare](/wiki/PrintNightmare) (2021) * [FORCEDENTRY](/wiki/FORCEDENTRY) (2021) * [Log4Shell](/wiki/Log4Shell) (2021) * [Account pre-hijacking](/wiki/Account_pre-hijacking) (2022) * [Retbleed](/wiki/Retbleed) (2022) * [Downfall](/wiki/Downfall_(security_vulnerability)) (2023) * [LogoFAIL](/wiki/LogoFAIL) (2023) * [Reptar](/wiki/Reptar_(vulnerability)) (2023) * [Terrapin](/wiki/Terrapin_attack) (2023) * [GoFetch](/wiki/GoFetch) (2024) * [Sinkclose](/wiki/Sinkclose) (2024) |
| Malware | |  |  | | --- | --- | | 2020 | * [Adrozek](/wiki/Adrozek) * [CovidLock](/wiki/CovidLock) * [Drovorub](/wiki/Drovorub) | | 2021 | * [Predator](/wiki/Predator_(spyware)) | | 2022 | * [BlackLotus](/wiki/BlackLotus) * [Cyclops Blink](/wiki/Cyclops_Blink) * [Pipedream](/wiki/Pipedream_(toolkit)) | | 2023 | * [Akira](/wiki/Akira_(ransomware)) | | 2024 | * [Gayfemboy](/wiki/Gayfemboy) | | 2025 | * [BootKitty](/wiki/BootKitty) | |

Retrieved from "<https://en.wikipedia.org/w/index.php?title=2023_MOVEit_data_breach&oldid=1315323229>"

[Categories](/wiki/Help:Category):

* [2023 in computing](/wiki/Category:2023_in_computing)
* [Progress Software](/wiki/Category:Progress_Software)
* [Computer security exploits](/wiki/Category:Computer_security_exploits)
* [Cyberattacks](/wiki/Category:Cyberattacks)
* [2023 data breaches](/wiki/Category:2023_data_breaches)
* [Hacking in the 2020s](/wiki/Category:Hacking_in_the_2020s)
* [Software bugs](/wiki/Category:Software_bugs)

Hidden categories:

* [Articles with short description](/wiki/Category:Articles_with_short_description)
* [Short description matches Wikidata](/wiki/Category:Short_description_matches_Wikidata)
* [Use American English from June 2023](/wiki/Category:Use_American_English_from_June_2023)
* [All Wikipedia articles written in American English](/wiki/Category:All_Wikipedia_articles_written_in_American_English)
* [Use mdy dates from June 2023](/wiki/Category:Use_mdy_dates_from_June_2023)
* [Pages using infobox mapframe with missing coordinates](/wiki/Category:Pages_using_infobox_mapframe_with_missing_coordinates)