MIT TRACE

MIT CTL Logo
Back to Main Dashboard

MOVEit exploit at ZELLIS triggers downstream breaches at BRITISH AIRWAYS and BBC

On 05/06/2023, payroll provider Zellis was compromised via the MOVEit Transfer zero‑day (CVE‑2023‑34362), leading to theft of employee data and extortion by CLOP. Multiple Zellis customers, including British Airways, BBC, Boots and Aer Lingus, confirmed staff data exposure, evidencing significant third‑party supply‑chain impact.

55

Estimated severity

55 / 100

87

Source reliability

87 / 100

Approximate Date

05/06/2023

Targeted Company

ZELLIS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

BRITISH AIRWAYS (Business process outsourcer)BBC (Business process outsourcer)BOOTS (Business process outsourcer)AER LINGUS (Business process outsourcer)

Geographic Impact

Country Targeted Company

United Kingdom

GBR

Other Affected Countries

No other affected countries reported

Target country

United Kingdom

Affected countries

United Kingdom

Impacted regions

United Kingdom · United Kingdom

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain coordination disruptionOperational disruption

Affected sectors

Professional & Business ServicesTransportationMedia & EntertainmentRetail

Affected departments

Information TechnologyHuman ResourcesLegal, Risk & Compliance

Attack Profile

Attack types

Exploitation of vulnerabilityZero-day exploitationData exfiltrationThird-party or partner compromiseExtortion

Attributed threat actors

CLOP

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.