MOVEit Transfer Breach 2023: Third-Party Risk at Scale
Updated: Aug 31
No one at 2,700 organizations clicked anything. Over a single holiday weekend, a zero-day in a trusted file-transfer product let a ransomware crew steal data at industrial scale, from companies, agencies, and universities, many of which had never heard of MOVEit until it took their data.
Case type: Supply chain / zero-day exploitation
Identified: May 28–30, 2023 Disclosed: May 31, 2023
Attribution: Clop (TA505 / FIN11)
Organizations spend enormous effort securing their own environments: training employees, implementing controls, monitoring for threats. Yet some of the most damaging incidents originate in places none of that effort can reach.
The 2023 MOVEit Transfer breach became one of the most widespread cybersecurity events on record, touching roughly 2,773 organizations and about 95 million people. It is also the second breach in this series with no deception in it anywhere: nobody was phished, nobody was called, nobody approved anything. Where Optus was one organization's forgotten door, MOVEit was a door thousands of organizations shared without knowing it. The incident demonstrates how third-party risk becomes enterprise risk at machine speed, and why vendor management and incident response preparedness, not just perimeter defense, determined who came through it well.
MOVEit Transfer is a managed file transfer platform, software organizations buy specifically to move their most sensitive data securely: payroll files, health records, pension data, student records. Thousands of organizations ran it, and thousands more were connected to it through vendors. On May 27, 2023, the Clop ransomware group began mass-exploiting a previously unknown SQL injection flaw in it, timed deliberately for the US Memorial Day weekend, when security teams run thin. At that moment, Progress Software, MOVEit's maker, did not yet know the vulnerability existed.
The exploitation planted a custom web shell, later dubbed LEMURLOOT, on each compromised server, installed as a file named human2.aspx to blend in beside MOVEit's legitimate human.aspx component. It could create administrator accounts disguised as a "Health Check Service" and drain the underlying database without any login. Forensic investigators later found the groundwork went back years: activity consistent with testing the exploit appeared as early as July 2021, and in the two weeks before the attack, automated reconnaissance harvested organization identifiers from servers, cataloging exactly whose data each one held. The heist was inventoried before it happened.
A customer reported unusual activity during the holiday weekend. Security firms converged on the pattern within days, and on May 31 Progress publicly disclosed the flaw, designated CVE-2023-34362 and later scored 9.8 out of 10, and shipped an emergency patch. The response was genuinely fast. It was also largely beside the point: the mass theft had been designed to finish before any patch could exist. Clop deployed no ransomware and encrypted nothing. It simply held the stolen data and, on June 5, publicly claimed "hundreds of organizations," giving victims until June 14 to open negotiations before publication began.
The victim list ultimately read like a cross-section of the economy: three of the Big Four accounting firms, major airlines and broadcasters, the largest US pension system's members through an actuarial vendor, dozens of universities, and government agencies in more than a dozen states. Clop's proceeds from the campaign were projected at $75 to $100 million. Many affected organizations were never targeted at all; they were exposed because, in Emsisoft's phrasing, they used a vendor which used a contractor which used a subcontractor which used MOVEit.
Nobody's controls failed. Everybody's data left.
For thousands of the affected organizations, every control they operated worked exactly as designed. Their employees clicked nothing. Their networks repelled nothing, because nothing ever touched them. Their data left through a platform two or three contracts away, run by people they had never met, patched on a schedule they did not control. The principle underneath is the uncomfortable one:
Organizations inherit risk from the technologies and vendors they choose to trust.
Every business relies on third parties: cloud providers, payroll vendors, HR platforms, managed service providers, software vendors, data processors, file transfer services. Each relationship expands capability, and each expands the attack surface. Eliminating vendor risk isn't realistic for any modern organization. Understanding it, mapping it, and preparing for its failure is.
You can't see your vendor's vendor
Leadership usually knows what services are purchased, what functions they support, and what the contracts say. What they often cannot see is what actually determines their exposure:
MOVEit made those hidden dependencies visible all at once, and in the worst possible way. Some of the largest academic institutions and government agencies in the country learned they were victims of software they had never purchased, never deployed, and never heard of. The dependency ran through a vendor's vendor, and the first notice arrived not from any contract's notification clause but from a criminal group's leak site.
Procurement signs it. Security lives with it.
Vendor management is often treated as a procurement or compliance activity. MOVEit demonstrates it is a security function, and an incident response function. Effective vendor risk programs can answer, for every vendor touching sensitive data:
Not one decision. A set of conditions.
There is no help desk to retrain here and no phishing template to recognize. The conditions that turned one flaw into everyone's breach were structural:
The breach was shared. The outcomes weren't.
The vulnerability was identical for everyone. The results were not. When a third-party breach lands, organizations must answer fast: Are we affected, directly or through a vendor? What data is involved? What legal obligations trigger, and on what clock? Who must be notified, and what should customers do? Organizations with rehearsed response processes assessed exposure, coordinated counsel and communications, and notified cleanly. Organizations without them spent weeks discovering their own vendor relationships in public, sometimes learning of their exposure from journalists or from Clop's leak site. Incident response planning is not a technical exercise. It is the difference between a manageable disruption and a rolling crisis, and MOVEit tested it across an entire economy simultaneously.
"Third-Party Risk Is Business Risk."
The MOVEit breach demonstrates that cybersecurity risk extends past organizational boundaries and travels along contracts. Thousands of organizations inherited a breach through technology relationships essential to their operations, while their own controls never failed. Three lessons survive the noise: third-party risk is business risk, vendor management is a governance function, and incident response maturity determined whether the same shared event became a footnote or a crisis.
The campaign also marked something the series will see again: attackers who no longer bother encrypting anything, because data itself is the leverage. When one flaw in shared infrastructure can produce ninety-five million victims in a weekend, the question for leadership isn't whether your vendors will ever be breached. It's whether you'll find out from them, or from the people who did it.
Because your security is only partly yours. The rest runs on software you bought, managed by people you've never met, patched on a schedule you don't control.
Sources
CISA, "#StopRansomware: CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability": https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a
Emsisoft, "Unpacking the MOVEit Breach: Statistics and Analysis": https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/
Cybersecurity Dive, "MOVEit mass exploit timeline: How the file-transfer service attacks entangled victims": https://www.cybersecuritydive.com/news/moveit-breach-timeline/687417/


Comments