United Kingdom
GBR
On 05/06/2023, payroll provider Zellis was compromised via the MOVEit Transfer zero‑day (CVE‑2023‑34362), leading to theft of employee data and extortion by CLOP. Multiple Zellis customers, including British Airways, BBC, Boots and Aer Lingus, confirmed staff data exposure, evidencing significant third‑party supply‑chain impact.
Estimated severity
55 / 100
Source reliability
87 / 100
Approximate Date
05/06/2023
Targeted Company
ZELLIS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
United Kingdom
GBR
No other affected countries reported
Target country
United Kingdom
Affected countries
Impacted regions
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone