LIVE MONITORING
Critical Confirmed Technology

MOVEit Transfer Mass Exploitation

Progress Software (MOVEit) data breach affecting 94.0M records.

9.5
Severity Score
Records Exposed
94.0M
Breach Date
May 2023
Attack Vector
SQL Injection (CVE-2023-34362)
Discovered
May 2023
Users Notified
June 2023
Financial Impact
$10B+ (aggregate)

Exposed Data Types

Names SSN Financial Data Medical Records Emails

The Cl0p ransomware group exploited a zero-day SQL injection vulnerability in MOVEit Transfer, a widely-used file transfer solution, affecting over 2,500 organizations worldwide including government agencies, healthcare providers, and financial institutions.

The Attack Chain

Attackers exploited CVE-2023-34362 to deploy web shells on vulnerable MOVEit servers, enabling data exfiltration at massive scale. The vulnerability allowed unauthenticated access to the MOVEit database.

Impact Assessment

Data Sensitivity
9.5
Scale
94.0M
Public Exposure
Critical