DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Deloitte Joins PwC and EY Among Big Four Firms Affected by MOVEit Exploitation

Deloitte, PwC and EY were all identified as affected by the MOVEit campaign. Public descriptions point to minimal or limited impact, while an EY–Bank of America settlement and Progress litigation continue in 2026.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—but the headline needs qualification. Deloitte, PwC and EY were all identified in industry reporting as organizations affected by the 2023 exploitation of Progress Software’s MOVEit file-transfer products. Public descriptions indicate that Deloitte’s impact was minimal and PwC’s was limited. EY is linked to a specific proposed settlement over Bank of America customer information handled through EY’s MOVEit environment. None of those facts, by themselves, proves that each firm’s entire network was breached, that all of its own data was stolen, or that a court has found liability.

The short version

  • Deloitte: identified as affected by the MOVEit campaign; secondary industry coverage characterized the impact as minimal.
  • PwC: reported as affected, with impact on the firm or its clients described as limited.
  • EY: involved in a proposed settlement concerning Bank of America-related personal information processed through EY.
  • Progress Software: continues to face multidistrict litigation. Its latest filing says 23 of 33 bellwether claims had been dismissed in whole or in part by May 31, 2026, while discovery and class-certification proceedings remained active.

The available public record does not establish a verified number of Deloitte or PwC victims, the exact files involved, or a Deloitte-specific settlement or regulatory penalty.

What the MOVEit attack was

MOVEit Transfer and MOVEit Cloud are enterprise software used to transfer sensitive files. Progress said it learned on May 28, 2023 that attackers had compromised customer-controlled MOVEit environments and exfiltrated personal data. The incident therefore involved several distinct stages:

  1. A vulnerability existed in a third-party file-transfer product.
  2. An attacker gained unauthorized access to an organization’s MOVEit server or cloud environment.
  3. Files stored or processed there could be copied out.
  4. Those files might contain the organization’s own information, client information, or data belonging to another party.

That chain is why “MOVEit victim” is a broad journalistic label. It does not automatically mean attackers entered a firm’s central corporate network or stole every category of data the firm held. The campaign is widely attributed to the Clop/Cl0p extortion group, although the sources available for this article do not provide a new primary attribution statement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Deloitte, PwC and EY compare

Firm What is publicly reported What remains unclear
Deloitte Identified as affected by the MOVEit exploitation. Industry coverage described the impact as minimal. The public record located for this article does not specify affected people, files, data categories, client relationships, notification totals, payment of an extortion demand, enforcement action, or a Deloitte-specific settlement.
PwC Reported as affected by the vulnerability, with impact on the firm or its clients described as limited. No organization-specific public figure or complete description of affected files and clients is established here.
EY A proposed EY–Bank of America settlement says EY handled certain Bank of America customer data through MOVEit and that personally identifiable information was involved. The settlement concerns a defined client-data and litigation context, not every EY system or every EY client.

The identification of the three firms comes from Cybersecurity Dive and a Trustwave professional-services threat report. Those are secondary sources for Deloitte’s and PwC’s characterization, so numerical claims should not be inferred from them.

What is actually known about Deloitte

The defensible description is that Deloitte was an affected MOVEit user or organization in the mass exploitation and that public industry reporting characterized the impact as minimal. That is narrower than saying “Deloitte’s systems were hacked” or that Deloitte lost a particular number of records.

No publicly located primary Deloitte notice or filing in the material available for this article specifies:

  • how many individuals were affected;
  • which files were accessed or exfiltrated;
  • the categories of personal information involved;
  • whether Deloitte client data was included;
  • whether Deloitte paid an extortion demand;
  • whether a regulator brought an enforcement action; or
  • whether Deloitte reached a settlement tied specifically to this incident.

Those gaps are important. Professional-services firms routinely process information for clients, so an affected file-transfer environment can expose third-party data without representing a compromise of the firm’s entire enterprise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is known about PwC

Available coverage says PwC confirmed that it was affected by the MOVEit vulnerability while describing the impact on the firm or its clients as limited. That supports reporting PwC as an affected organization, but not assigning it a mass-record total or claiming that a broad set of customer files was stolen.

As with Deloitte, the exact scope depends on the particular MOVEit environment, the files stored there and any later investigation or notice. A delayed notification can reflect the time needed to determine which records were involved; it does not by itself establish when an intrusion began.

What the EY–Bank of America settlement covers

The settlement website says EY used MOVEit in the ordinary course of business to handle certain Bank of America data. It identifies personally identifiable information belonging to some Bank of America customers and places the incident between May 27 and May 31, 2023.

The proposed agreement resolves claims against EY and Bank of America in that particular action. It does not resolve claims against Progress, and it should not be treated as a universal settlement for everyone who received a MOVEit-related notice. The settlement’s final-approval hearing is scheduled for October 15, 2026. The administrator lists October 8, 2026 as the claim deadline; instructions are available at the claims-filing page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why “victim” does not mean legal liability

“Victim” is shorthand for an organization affected by exploitation. It does not establish negligence, failure to patch, legal responsibility, identity theft, or a court finding against the organization. Liability questions depend on the facts and the claims in a particular case.

Progress’s filings describe ongoing litigation and say the company cannot yet reasonably estimate potential losses, judgments, settlements, fines or penalties. A dismissal of a claim may concern pleading, standing, causation or another legal issue; it does not mean the underlying MOVEit incident did not occur or that every claim against every defendant has ended.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Where the litigation stands in 2026

Progress reports that the federal cases are centralized in multidistrict litigation in the U.S. District Court for the District of Massachusetts. Its filing for the quarter ended May 31, 2026 states that:

  • dismissal rulings occurred in 2025 and January 2026;
  • 23 of 33 claims asserted by bellwether plaintiffs had been dismissed in whole or in part;
  • fact discovery was scheduled to conclude on September 29, 2026;
  • class-certification briefing was scheduled to begin on August 28, 2026; and
  • the company did not expect the MDL to conclude within the following 12 months.

The filing is available through the Securities and Exchange Commission. Key MDL orders, including July 31, 2025 dismissal rulings and early-2026 orders on reconsideration and standing, are recorded at GovInfo.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What affected individuals should do

  1. Read the exact notice. Identify the organization named as the sender or data custodian, the incident dates and the information categories listed.
  2. Match the case to the notice. Receiving a MOVEit notice from another company does not automatically make you eligible for the EY–Bank of America settlement.
  3. Use only the named administrator. File through the settlement or notification website identified in your notice, not an unrelated search result.
  4. Follow the notice’s protection instructions. If credit monitoring, fraud assistance or account changes are offered, use the enrollment instructions and deadlines supplied there.
  5. Watch for misuse. Be cautious with unexpected account, tax, payroll or password-reset messages, particularly if the notice says government identifiers or financial information were involved.

What remains unanswered

Publicly available reporting supports Deloitte’s inclusion in the MOVEit campaign and a minimal-impact characterization, but it does not provide a verified Deloitte record count or detailed data inventory. PwC’s public description is similarly limited. EY’s proposed settlement supplies a concrete Bank of America-related context, while leaving separate EY environments and other client relationships outside that agreement.

The most accurate conclusion is therefore specific, not sweeping: Deloitte, PwC and EY were all caught up in the MOVEit exploitation, but their publicly described exposure was not identical. Technical impact, the ownership of affected data, and legal responsibility must be evaluated separately for each notice and proceeding.

Frequently Asked Questions

Was KPMG part of this specific Big Four MOVEit grouping?

The sources used here identify Deloitte, PwC and EY. They do not establish KPMG as part of this specific grouping.

Does a MOVEit notice prove that my identity was stolen?

No. A notice indicates that information may have been accessed or exposed; it does not by itself prove identity theft. Follow the notice’s monitoring and fraud-prevention instructions.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.