Skip to main content
Mallory
Back to intelligence
third-party-vendor-breachransomware-group-operationactively-exploited-vulnerabilitymass-credential-exposure

Cl0p Exploited MOVEit Zero-Days to Steal Data From Thousands of Organizations

Updated 7d agoFirst seen May 25, 202678 sources

The Cl0p extortion group exploited multiple critical SQL injection flaws in Progress Software's MOVEit Transfer platform, beginning with the zero-day later tracked as CVE-2023-34362, to breach organizations worldwide and steal large volumes of data. Researchers and government agencies linked the campaign to Cl0p, also tracked as Lace Tempest, FIN11, and TA505, and reported that attackers often deployed the LemurLoot web shell and exfiltrated files within minutes; in some cases, the malware could also pull Azure Blob storage details and credentials from MOVEit settings. Progress disclosed and patched additional MOVEit vulnerabilities, including CVE-2023-35036 and CVE-2023-35708, as incident responders warned that victim counts would continue to rise through delayed breach notifications and downstream third-party exposure.

The fallout spread across government, finance, healthcare, education, insurance, professional services, and major global brands, with disclosures naming entities such as EY, PwC, Sony and Pan-American Life Insurance Group among the affected organizations or reported victims. By later tallies, the campaign had compromised thousands of organizations and tens of millions of individuals, while Cl0p shifted from encryption to data-theft and extortion, publishing stolen information from nonpaying victims on leak sites. The incident triggered broad regulatory scrutiny, lawsuits, response costs, and supply-chain consequences as organizations discovered that exposure often came through vendors and file-transfer partners rather than direct compromise.

Share:
Cl0p Exploited MOVEit Zero-Days to Steal Data From Thousands of Organizations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

61 events from the most recent confirmed update back to the earliest known activity.

61 EVENTS
Jun 28, 20242y ago

Known MOVEit toll reaches 2,773 organizations and 95.8 million people

As of 2024-06-28, Emsisoft's tracking put the MOVEit campaign at 2,773 organizations and 95,788,491 affected individuals. U.S.-based entities made up most known victims, with education, healthcare, and finance/professional services among the hardest-hit sectors.

Dec 29, 20232y ago

Pan-American Life Insurance Group reports MOVEit-linked breach

Pan-American Life Insurance Group disclosed a data breach affecting about 105,000 individuals that was tied to the MOVEit incident. The disclosure illustrated the long tail of victim notifications months after the initial exploitation.

Dec 5, 20232y ago

Aetna Life Insurance discloses MOVEit breach affecting 300,000+ people

Aetna Life Insurance Company disclosed that a MOVEit Transfer-related breach impacted more than 300,000 individuals. The notice added another major insurance-sector victim to the long tail of breach disclosures tied to Cl0p's mass exploitation campaign.

teiss - News - Aetna Life Insurance Company says MOVEit Transfer breach impacted over 300k individuals
Dec 4, 20232y ago

Blue Shield of California discloses MOVEit breach affecting hundreds of thousands

Blue Shield of California disclosed that a MOVEit-related breach affected hundreds of thousands of members. The notice added another major healthcare insurer to the continuing stream of downstream victim disclosures tied to the Cl0p MOVEit exploitation campaign.

Hundreds of Thousands of Blue Shield of California Members Affected by MOVEit Hack
Nov 24, 20233y ago

Medical College of Wisconsin discloses MOVEit-linked breach

The Medical College of Wisconsin said a MOVEit Transfer-related breach affected more than 240,000 individuals. The disclosure added another healthcare-sector victim to the long tail of organizations reporting impact from the Cl0p exploitation campaign.

teiss - News - Medical College of Wisconsin says MOVEit Transfer breach affected more than 240,000 individuals
Nov 20, 20233y ago

Welltok discloses MOVEit breach affecting about 1.6 million people

Welltok was reported as a victim of the MOVEit Transfer mass exploitation campaign, with the breach affecting roughly 1.6 million individuals. The disclosure added another major healthcare-sector downstream victim to the continuing stream of breach notifications tied to Cl0p's attacks.

Welltok MOVEit hack impacts 1.6M individuals | Cybernews

MESVision discloses MOVEit breach affecting nearly 350,000 patients

California-based MESVision said a MOVEit Transfer-related breach impacted close to 350,000 patients. The disclosure added another healthcare-sector victim to the continuing stream of downstream breach notifications tied to the Cl0p MOVEit exploitation campaign.

teiss - News - California-based MESVision says MOVEit Transfer breach impacted close to 350k patients
Nov 16, 20233y ago

Maine says MOVEit breach affected about 1.3 million residents

Maine state government disclosed that a MOVEit-related data breach impacted roughly 1.3 million residents. The notice added a major U.S. state-government victim and one of the larger publicly reported population-level exposures tied to the Cl0p MOVEit campaign.

Maine State Government’s MOVEit Data Breach Basically Impacted All 1.3 Million Residents - CPO Magazine

Westat reports MOVEit-linked data breach

Westat, Inc. disclosed a data breach resulting from exploitation of the MOVEit software vulnerability. The notice added another downstream victim to the long tail of organizations publicly reporting impact from the Cl0p MOVEit campaign.

teiss - News - Westat, Inc. reports data breach due to MOVEit software vulnerability
Nov 13, 20233y ago

Sutter Health says MOVEit breach affected over 845,000 patients

SC Media reported that Sutter Health disclosed a MOVEit-linked data breach affecting more than 845,000 patients. The notice added another major healthcare-sector victim to the long tail of downstream breach disclosures tied to Cl0p's mass exploitation campaign.

MOVEit hack hits over 845K Sutter Health patients | brief | SC Media
Nov 9, 20233y ago

Sun Life Financial says MOVEit breach affected 212,000+ U.S. customers

Sun Life Financial disclosed that a MOVEit-related data breach impacted more than 212,000 U.S. customers. The notice added another insurance-sector victim to the continuing stream of downstream breach disclosures tied to the Cl0p MOVEit exploitation campaign.

teiss - News - Sun Life Financial says MOVEit data breach impacted more than 212k US customers
Oct 30, 20233y ago

NASCO discloses MOVEit-linked breach affecting about 800,000 people

Healthcare technology company NASCO was reported as a victim of the MOVEit Transfer mass exploitation campaign, with data exposure affecting roughly 800,000 individuals. The disclosure added another major downstream victim to the long-running stream of breach notifications tied to Cl0p's attacks.

NASCO exposes data of 800K people in MOVEit breach | Cybernews
Oct 26, 20233y ago

CCleaner confirms MOVEit-linked data breach

CCleaner confirmed that it was affected by the MOVEit mass exploitation campaign, adding another named software company to the list of publicly disclosed victims tied to Cl0p's attacks. The disclosure extended the campaign's known impact into the consumer software sector.

CCleaner confirms data breach via MOVEit attack | Cybernews

MOVEit campaign impact surpasses 2,550 organizations and 66 million people

By October 2023, reporting cited more than 2,550 affected organizations and roughly 66 million impacted individuals. The incident had also triggered major financial, legal, and regulatory consequences for Progress, including lawsuits and an SEC inquiry.

Oct 13, 20233y ago

Texas-based credit union says MOVEit breach affected 102,000 customers

A Texas-based credit union disclosed that a MOVEit Transfer-related data breach impacted about 102,000 customers. The notice added another financial-sector victim to the long tail of downstream breach disclosures tied to Cl0p's mass exploitation campaign.

teiss - News - Texas-based credit union says MOVEit Transfer breach impacted 102k customers
Aug 28, 20233y ago

Additional MOVEit victim data is leaked by Cl0p

Later in August, Cl0p released more data from MOVEit victims, continuing the extortion campaign and increasing the exposure of stolen records. The leaks underscored that many affected organizations had not reached agreements with the attackers.

Aug 25, 20233y ago

Standard Insurance says NTT DATA MOVEit breach exposed 300,000+ customers

Reporting on 2023-08-25 said data belonging to more than 300,000 Standard Insurance customers was exposed through NTT DATA's MOVEit-related breach. The disclosure added another downstream victim relationship to the expanding impact of the Cl0p MOVEit exploitation campaign.

Data of 300K+ Standard Insurance customers exposed in MOVEit-related NTT DATA attack | Cybernews
Aug 16, 20233y ago

Cl0p begins leaking MOVEit victim data publicly

In August 2023, Cl0p started publishing data stolen in the MOVEit campaign, escalating pressure on victims through extortion. Public leaks marked a shift from claims of compromise to visible release of exfiltrated information.

Aug 3, 20233y ago

Serco discloses MOVEit-linked data breach

U.S. government contractor Serco publicly disclosed a data breach resulting from the MOVEit mass exploitation campaign. The disclosure added another notable downstream victim connected to sensitive government-related services.

US govt contractor Serco discloses data breach after MoveIT attacks
Jul 31, 20233y ago

CMS says MOVEit breach exposed data of 612,000 Medicare beneficiaries

On 2023-07-31, the Centers for Medicare & Medicaid Services disclosed that a MOVEit-linked breach exposed personal data belonging to about 612,000 Medicare beneficiaries. The notice added a major U.S. government healthcare impact disclosure to the expanding list of downstream victims tied to the Cl0p campaign.

MoveIT breach exposes data of 612K Medicare beneficiaries, CMS says | Cybersecurity Dive
Jul 28, 20233y ago

Medicaid administrator breach exposes data of more than 8 million people

A Medicaid administrator disclosed a MOVEit-linked breach affecting more than 8 million people. The report marked a major escalation in downstream impact, adding one of the largest publicly reported exposure totals tied to the Cl0p MOVEit campaign at that time.

Medicaid administrator breach exposes 8M+ people | Cybernews
Jul 27, 20233y ago

Maximus and Deloitte linked to MOVEit breach affecting millions

Reporting on 2023-07-27 said government services contractor Maximus and consultant Deloitte were among organizations affected by the MOVEit exploitation campaign. The disclosure highlighted exposure of healthcare-related files affecting millions of people, adding major named victims to the incident's growing toll.

Millions of people's healthcare files accessed by Clop gang
Jul 21, 20233y ago

DHL investigates possible MOVEit breach exposure

On 2023-07-21, reporting said DHL was investigating whether it had been affected by the MOVEit Transfer exploitation campaign. The report added a major global logistics brand to the list of organizations publicly responding to possible compromise tied to Cl0p's attacks.

DHL investigating MOVEit breach as number of victims surpasses 20 million | The Record from Recorded Future News
Jul 20, 20233y ago

Ofcom discloses MOVEit breach and says it will not pay ransom

On 2023-07-20, UK telecom regulator Ofcom said it was affected by the MOVEit Transfer mass exploitation campaign and stated it would not pay a ransom demand. The report also identified Ireland's telecom regulator ComReg as another newly disclosed victim, adding European regulators to the growing list of impacted organizations.

Ofcom says it won't pay ransom, as new MOVEit hack victims come forward | TechCrunch
Jul 19, 20233y ago

Estée Lauder and Mary Kay reported as MOVEit victims

A 2023-07-19 report said cosmetics companies Estée Lauder and Mary Kay were on the growing list of organizations affected by the Cl0p MOVEit Transfer exploitation campaign. The disclosure added newly named consumer-brand victims to the expanding roster of impacted companies.

Estee Lauder joins Mary Kay on MOVEit victim list | Cybernews
Jul 17, 20233y ago

TJ Maxx and TomTom confirm MOVEit-related data incidents

Reporting on 2023-07-17 said TJ Maxx and TomTom were among the latest organizations to confirm data incidents tied to the Cl0p MOVEit Transfer exploitation campaign. The disclosures added major retail and navigation-technology brands to the growing list of publicly identified victims.

TJ Maxx, Shutterfly, TomTom latest organizations to confirm MOVEit breaches | The Record from Recorded Future News

Vitesco Technologies reported as a MOVEit victim

TechMonitor reported that Vitesco Technologies was among the organizations identified as victims of the Cl0p MOVEit Transfer exploitation campaign. The report added another named enterprise victim to the expanding list of affected companies.

MOVEit Transfer vulnerability: Vitesco among new Cl0p 'victims'
Jul 14, 20233y ago

Colorado State University discloses MOVEit-related data breach

Colorado State University said a data breach tied to the MOVEit Transfer exploitation campaign affected students and staff. The disclosure added another higher-education victim to the growing list of organizations impacted by Cl0p's mass exploitation.

Colorado State University says data breach impacts students, staff

Shutterfly says MOVEit incident did not affect customer data

Shutterfly said it was affected by the Cl0p-linked MOVEit campaign but stated that its investigation found no impact to customer data. The statement added a new named victim response and clarified the scope of exposure at the company.

Shutterfly says Clop ransomware attack did not impact customer data

MOVEit victim count reaches hundreds of organizations

By mid-July, incident tracking showed the mass exploitation had spread to hundreds of organizations and many downstream third parties. Government, healthcare, education, finance, pensions, and manufacturing were among the affected sectors.

Jul 12, 20233y ago

PBI discloses MOVEit breach affecting more than 370,000 people

On 2023-07-12, reporting said healthcare organization PBI suffered a MOVEit-linked data breach exposing details of more than 370,000 people. The disclosure added another healthcare-sector victim to the growing list of organizations impacted by Cl0p's mass exploitation campaign.

Breach of PBI exposes details of 370K+ people | Cybernews

Another health system discloses MOVEit-linked data breach

Becker's Hospital Review reported that another health system had become a disclosed victim of the MOVEit Transfer mass exploitation campaign. The report added a new healthcare-sector victim to the growing list of organizations publicly acknowledging impact from Cl0p's attacks.

MOVEit data breach claims another health system victim - Becker's Hospital Review | Healthcare News & Analysis
Jul 10, 20233y ago

Choice Hotels says Radisson guest data was exposed in MOVEit breach

On 2023-07-10, reporting said Choice Hotels disclosed that guest information from Radisson Hotels Americas was exposed through the MOVEit Transfer attacks. The report added a major hospitality-sector victim relationship to the growing list of downstream organizations affected by the Cl0p exploitation campaign.

Choice Hotels: Radisson guest info breached in MOVEit attacks | Cybernews

Deutsche Bank and Postbank reported impacted by MOVEit breach

A 2023-07-10 report said Deutsche Bank and its Postbank unit were affected by the Cl0p MOVEit Transfer exploitation campaign, exposing customer data. The disclosure added a major European banking-sector victim to the growing list of publicly identified organizations tied to the mass exploitation.

Deutsche Bank customer data leaked | Cybernews
Jul 7, 20233y ago

CISA warns on three new MOVEit vulnerabilities

On 2023-07-07, CISA warned about three newly disclosed MOVEit Transfer vulnerabilities as additional organizations continued reporting breaches tied to the broader exploitation wave. The alert marked a further technical escalation beyond the earlier June patches, indicating more flaws had been identified in the product.

Three new MOVEit bugs spur CISA warning as more victims report breaches | The Record from Recorded Future News
Jul 6, 20233y ago

Ciena says limited data was impacted in MOVEit attack

Ciena disclosed that it was affected by the MOVEit Transfer attack and said the incident had a limited impact on data. The statement added another named enterprise victim to the growing list of organizations publicly acknowledging exposure tied to the Cl0p campaign.

Ciena Says ‘Limited’ Data Impacted In MOVEit Attack | CRN
Jun 30, 20233y ago

TIAA linked to MOVEit breach affecting teachers' retirement data

On 2023-06-30, reporting said schools disclosed that TIAA, a major U.S. retirement fund serving teachers and academic institutions, was targeted in the MOVEit hacking campaign. The report added another major financial and education-linked victim relationship to the growing list of organizations affected by Cl0p's mass exploitation.

Schools say US teachers' retirement fund was targeted by MOVEit hackers | TechCrunch
Jun 29, 20233y ago

Honeywell reported as a MOVEit breach victim

Reporting on 2023-06-29 said Honeywell had been compromised in the MOVEit Transfer hacking campaign. The disclosure added a major industrial and technology company to the growing list of organizations publicly identified as affected by Cl0p's mass exploitation.

Honeywell Servers Compromised by MOVEit Hackers

HHS says MOVEit breach may have exposed data of 100,000 people

On 2023-06-29, CNN reported that the U.S. Department of Health and Human Services was affected by the MOVEit cyberattack and said at least 100,000 people could have had their data exposed. The disclosure added a major U.S. federal health-sector victim to the growing list of organizations impacted by Cl0p's mass exploitation campaign.

At least 100,000 could have had data exposed after US health department was hit by global cyberattack | CNN Politics
Jun 27, 20233y ago

UCLA and Siemens Energy confirm MOVEit-related breaches

Reporting on 2023-06-27 said UCLA and Siemens Energy had confirmed breaches tied to the MOVEit Transfer exploitation campaign. The disclosures added a major U.S. university and a global energy technology company to the growing list of publicly identified victims.

UCLA, Siemens Energy latest MOVEit victims to confirm breaches | The Record from Recorded Future News
Jun 23, 20233y ago

Cl0p claims GUS Canada as a MOVEit victim

On 2023-06-23, reporting said Cl0p had added GUS Canada to its list of organizations allegedly compromised in the MOVEit Transfer exploitation campaign. The claim expanded the roster of publicly named victims beyond those already reported such as PwC and Sony.

PwC, Sony And Now GUS Canada Data Breach Claimed By Cl0p
Jun 22, 20233y ago

CalPERS linked to MOVEit breach

On 2023-06-22, reporting said the California Public Employees' Retirement System (CalPERS) was affected by the MOVEit Transfer exploitation campaign. The disclosure added a major U.S. public pension fund to the growing list of organizations impacted by the Cl0p-linked mass exploitation.

MOVEit hack reaches California state workers' pension fund | StateScoop

Major brands are reported as possible MOVEit victims

By 2023-06-22, reporting linked additional prominent organizations such as EY, PwC, and Sony to the expanding MOVEit victim list. This reflected the campaign's growing impact across major enterprises and service providers.

Jun 21, 20233y ago

Telos confirms MOVEit-linked data breach

Telos confirmed that it suffered a data breach related to exploitation of the MOVEit Transfer vulnerability. The disclosure added another named enterprise and government-services contractor to the growing list of organizations affected by the Cl0p-linked mass exploitation campaign.

Telos confirms data breach over MOVEit bug | Cybernews
Jun 20, 20233y ago

Cl0p says it does not have BBC, BA, and Boots data

On 2023-06-20, Cl0p reportedly claimed it did not possess stolen data from the BBC, British Airways, or Boots, despite those organizations being linked to the MOVEit fallout through payroll provider Zellis. The statement added a notable attacker response about the scope of data theft affecting several high-profile UK organizations.

MOVEit hack: Gang claims not to have BBC, BA and Boots data
Jun 16, 20233y ago

Transport for London says MOVEit breach exposed data of about 13,000 drivers

Transport for London disclosed that the MOVEit hack compromised data belonging to about 13,000 drivers. The announcement added a major UK transport-sector organization to the growing list of publicly identified victims tied to the Cl0p MOVEit exploitation campaign.

teiss - News - Transport for London says MOVEit hack compromised the data of about 13,000 drivers
Jun 15, 20233y ago

DOE and several federal agencies reported hit by MOVEit breach

Federal News Network reported that the U.S. Department of Energy was among several federal agencies affected by the MOVEit Transfer exploitation campaign. The report added a specific set of federal-government victims to the growing list of organizations impacted by Cl0p's mass exploitation.

Energy Department among ‘several’ federal agencies hit by MOVEit breach | Federal News Network

Progress patches third MOVEit vulnerability

On 2023-06-15, Progress patched another MOVEit Transfer flaw, CVE-2023-35708. The additional remediation showed that the incident involved multiple serious vulnerabilities, not just the original zero-day.

Jun 12, 20233y ago

Illinois reported impacted by MOVEit ransomware campaign

A 2023-06-12 report said Illinois was affected by the wide-ranging MOVEit/Cl0p attack, adding another U.S. state government victim to the growing list of publicly identified organizations. The disclosure further showed the campaign's expanding impact on public-sector entities.

Illinois Impacted by Wide-Ranging Ransomware Attack
Jun 9, 20233y ago

Progress patches second MOVEit vulnerability

Progress released fixes for a second MOVEit Transfer vulnerability, CVE-2023-35036, as investigators uncovered additional security issues during response efforts. The patch was part of an ongoing effort to contain the exploitation campaign.

Minnesota Department of Education discloses MOVEit-linked student data breach

CBS reported that the Minnesota Department of Education was hit in the global MOVEit cyberattack, exposing data on about 95,000 students. The disclosure added a new public-sector victim to the growing list of organizations affected by the mass exploitation campaign.

Global MOVEit cyberattack hits Minnesota Department of Education - CBS Minnesota
Jun 8, 20233y ago

Nova Scotia Health says MOVEit breach affected 100,000 people

Nova Scotia Health disclosed that the MOVEit-related breach affected about 100,000 individuals. The notice adds a quantified healthcare-sector impact disclosure tied to the long tail of downstream victim notifications from the Cl0p MOVEit campaign.

Nova Scotia Health Says 100,000 Affected by MOVEit Hack

Wave of MOVEit breach disclosures begins

By 2023-06-08, organizations were publicly disclosing data breaches tied to the MOVEit flaw as the victim count began to rise. Reporting indicated the incident was expanding beyond direct users to downstream organizations whose data was handled by affected third parties.

Jun 7, 20233y ago

Cl0p claims Zellis-linked breaches and sets June 14 extortion deadline

On 2023-06-07, the Russian-speaking Cl0p gang claimed responsibility for breaches affecting BBC and British Airways employee data via payroll provider Zellis. The group said it had data from hundreds of companies and warned victims to negotiate by June 14 before stolen information would be published.

Clop: Russian-speaking cyber gang claims credit for hack of BBC and British Airways employee data | CNN Business
Jun 6, 20233y ago

University of Rochester and Nova Scotia identified as early MOVEit victims

Reporting on 2023-06-06 identified the University of Rochester and the government of Nova Scotia as among the first known North American organizations affected by the MOVEit Transfer exploitation campaign. The disclosure added specific early victims to the emerging list of organizations impacted by Cl0p's mass exploitation.

University of Rochester, Nova Scotia first known MoveIT victims in North America | The Record from Recorded Future News

Researchers warn of widespread global MOVEit exploitation

By early June, Rapid7 and other researchers described the MOVEit activity as a widespread threat affecting high-value targets across sectors, sizes, and geographies. Independent tracking already showed a double-digit number of organizations with stolen data, including U.S. government and banking entities.

Jun 5, 20233y ago

BBC, British Airways, and Boots linked to MOVEit fallout

On 2023-06-05, BBC reporting identified the BBC, British Airways, and Boots as among the organizations affected by the MOVEit cyberattack through payroll provider Zellis. The report added several high-profile UK brands to the early list of victims tied to the expanding exploitation campaign.

MOVEit hack: BBC, BA and Boots among cyber attack victims
May 31, 20233y ago

Progress discloses exploited MOVEit zero-day and issues first patch

On 2023-05-31, Progress Software disclosed an actively exploited SQL injection vulnerability in MOVEit Transfer, later tracked as CVE-2023-34362 with a CVSS score of 9.8. The company released fixes and urged customers to take immediate mitigation steps.

May 29, 20233y ago

Customer reports unusual MOVEit activity over Memorial Day weekend

A MOVEit customer observed suspicious activity during the U.S. Memorial Day weekend, helping surface the broader compromise. This activity preceded public disclosure and indicated active exploitation in the wild.

May 27, 20233y ago

Cl0p begins exploiting MOVEit Transfer zero-day

Mandiant reported that the Cl0p extortion operation began exploiting a SQL injection zero-day in MOVEit Transfer on 2023-05-27. Attackers used the LemurLoot webshell and in some cases stole data within minutes, including potentially Azure Blob storage credentials from compromised systems.

MOVEit breach toll surges further in later reporting

By May 2026, reporting indicated the data breach toll tied to Cl0p's MOVEit attacks had continued to rise beyond earlier counts. This reflected the prolonged disclosure cycle and ongoing identification of affected organizations and individuals.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.