Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Clop Exploited MOVEit Transfer to Steal Data: What Happened in 2023

The 2023 MOVEit breach was a data-theft and extortion campaign exploiting Progress Software’s file-transfer product. Here’s what affected people should know.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In 2023, attackers exploited a vulnerability in Progress Software’s MOVEit Transfer file-sharing software to steal data from organizations and threaten extortion. Mandiant’s earliest observed evidence of exploitation was May 27, four days before Progress publicly disclosed the flaw as CVE-2023-34362. The campaign put people’s information at risk through organizations that used MOVEit—not because every affected person had a direct relationship with the software.

What happened in the MOVEit breach?

MOVEit Transfer is a managed file-transfer product organizations use to exchange files. Attackers exploited CVE-2023-34362 in the application, then used access to affected systems to find and download files. Those files could contain information about customers, employees, beneficiaries, or other people whose records an organization handled.

Progress disclosed the vulnerability on May 31, 2023. Mandiant reported that its earliest evidence of exploitation dated to May 27. It observed a MOVEit-specific C# web shell called LEMURLOOT being deployed, with some cases showing data theft within minutes of deployment. Mandiant described the attackers enumerating files and folders, retrieving configuration information, and downloading files.

The campaign reached organizations in multiple industries and countries. The UK National Cyber Security Centre (NCSC) said organizations around the world were affected. Its description of customer and employee data being stolen reflects the supply-chain nature of the incident: files held by one organization could contain personal data about people connected to another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was this ransomware, and who was responsible?

The activity involved data theft and extortion threats, but the technical accounts describe stealing files—not encrypting every victim’s systems. Do not assume that a MOVEit breach notice means your files were encrypted.

Mandiant recorded a June 6, 2023, post on the CL0P leak site claiming responsibility. Separately, Mandiant initially tracked the activity as UNC4857 and later merged it into FIN11 based on overlaps in targeting, infrastructure, certificates, and leak-site activity. The public claim and Mandiant’s analytic attribution are related but distinct evidence.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

In its June 2023 analysis, Mandiant said victims had not initially received ransom demands and that its team had not yet directly observed extortion emails to confirmed victims at the time it published. That was a time-specific observation, not a conclusion about every later case.

How many people were affected?

There is no single final campaign-wide total established by the cited disclosures. Breach notices count particular organizations, populations, and investigations; they should not be added together and presented as the total number of people affected by MOVEit.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Organization or contractor Notice and population Information and investigation Protection described
Maximus and CMS On November 16, 2023, the Centers for Medicare & Medicaid Services (CMS) said it and contractor Maximus were notifying 330,000 current Medicare beneficiaries who may have been impacted. CMS described possible exposure of personal and Medicare information. A 24-month credit-monitoring offer.
WPS and CMS In a later notice in 2024, CMS said WPS and CMS were notifying 946,801 current people with Medicare whose information may have been exposed. CMS said WPS’s later review identified copied files that an earlier investigation had not found evidence of being copied. Not stated in the cited CMS notice information summarized here.

These are separate contractor incidents and notices, not a complete accounting of the campaign. The number and type of records involved, whether files were confirmed copied, and any protective services offered can differ from one organization’s investigation to another.

What should you do if you receive a MOVEit breach notice?

  1. Check who sent the notice. Identify the organization or contractor named and confirm that the notice is intended for you. If anything is unclear, contact the organization through a channel you already trust rather than relying only on contact details in an unexpected message.
  2. Read the notice for the specific data involved. Look for whether it names personal information, Medicare information, or other records, and whether the organization says exposure is possible or that files were found to have been copied.
  3. Follow the notice’s instructions. Use any credit-monitoring or other protection offered according to the notice’s stated eligibility, enrollment process, and time limit. Do not assume a service mentioned in one organization’s notice is available to everyone affected by MOVEit.
  4. Keep the notice and related records. Retain the letter or message and any confirmation of enrollment or steps you take, so you can refer to the organization’s description of the incident and its instructions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should affected organizations do?

Organizations should follow Progress Software’s current security guidance for MOVEit, apply the vendor’s fixes and mitigations, and investigate whether the application or related infrastructure was accessed and whether data was exposed. Mandiant’s incident-response guidance covers containment, application and infrastructure hardening, logging, and threat hunting. Because vendor instructions can change, use Progress’s live guidance rather than relying on a historical incident summary.

The NCSC says: “The NCSC’s position, along with law enforcement, is that we don’t endorse, promote or encourage the payment of ransoms.” Organizations should coordinate incident response and legal obligations with appropriate professionals rather than treating ransom payment as a guaranteed route to data recovery or deletion.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.