United States
USA
Beginning in late May 2023, CL0P mass‑exploited a zero‑day SQL injection flaw (CVE‑2023‑34362) in PROGRESS SOFTWARE’s MOVEit Transfer to install web shells and steal data at scale. Advisories documented extensive third‑party exposure, with breaches at service providers cascading to downstream customers (e.g., ZELLIS to BBC, BOOTS, BRITISH AIRWAYS). Emsisoft tracked thousands of affected organizations and tens of millions of impacted individuals. CISA and NCSC urged entities to take MOVEit systems offline and patch.
Estimated severity
82 / 100
Source reliability
93 / 100
Approximate Date
31/05/2023
Targeted Company
PROGRESS SOFTWARE
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
United States
USA
United Kingdom
GBR
Canada
CAN
Target country
United States
Affected countries
Impacted regions
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
No information
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone