The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Yes—but the headline needs qualification. Deloitte, PwC and EY were all identified in industry reporting as organizations affected by the 2023 exploitation of Progress Software’s MOVEit file-transfer products. Public descriptions indicate that Deloitte’s impact was minimal and PwC’s was limited. EY is linked to a specific proposed settlement over Bank of America customer information handled through EY’s MOVEit environment. None of those facts, by themselves, proves that each firm’s entire network was breached, that all of its own data was stolen, or that a court has found liability.
The short version
- Deloitte: identified as affected by the MOVEit campaign; secondary industry coverage characterized the impact as minimal.
- PwC: reported as affected, with impact on the firm or its clients described as limited.
- EY: involved in a proposed settlement concerning Bank of America-related personal information processed through EY.
- Progress Software: continues to face multidistrict litigation. Its latest filing says 23 of 33 bellwether claims had been dismissed in whole or in part by May 31, 2026, while discovery and class-certification proceedings remained active.
The available public record does not establish a verified number of Deloitte or PwC victims, the exact files involved, or a Deloitte-specific settlement or regulatory penalty.
What the MOVEit attack was
MOVEit Transfer and MOVEit Cloud are enterprise software used to transfer sensitive files. Progress said it learned on May 28, 2023 that attackers had compromised customer-controlled MOVEit environments and exfiltrated personal data. The incident therefore involved several distinct stages:
- A vulnerability existed in a third-party file-transfer product.
- An attacker gained unauthorized access to an organization’s MOVEit server or cloud environment.
- Files stored or processed there could be copied out.
- Those files might contain the organization’s own information, client information, or data belonging to another party.
That chain is why “MOVEit victim” is a broad journalistic label. It does not automatically mean attackers entered a firm’s central corporate network or stole every category of data the firm held. The campaign is widely attributed to the Clop/Cl0p extortion group, although the sources available for this article do not provide a new primary attribution statement.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
How Deloitte, PwC and EY compare
| Firm | What is publicly reported | What remains unclear |
|---|---|---|
| Deloitte | Identified as affected by the MOVEit exploitation. Industry coverage described the impact as minimal. | The public record located for this article does not specify affected people, files, data categories, client relationships, notification totals, payment of an extortion demand, enforcement action, or a Deloitte-specific settlement. |
| PwC | Reported as affected by the vulnerability, with impact on the firm or its clients described as limited. | No organization-specific public figure or complete description of affected files and clients is established here. |
| EY | A proposed EY–Bank of America settlement says EY handled certain Bank of America customer data through MOVEit and that personally identifiable information was involved. | The settlement concerns a defined client-data and litigation context, not every EY system or every EY client. |
The identification of the three firms comes from Cybersecurity Dive and a Trustwave professional-services threat report. Those are secondary sources for Deloitte’s and PwC’s characterization, so numerical claims should not be inferred from them.
What is actually known about Deloitte
The defensible description is that Deloitte was an affected MOVEit user or organization in the mass exploitation and that public industry reporting characterized the impact as minimal. That is narrower than saying “Deloitte’s systems were hacked” or that Deloitte lost a particular number of records.
No publicly located primary Deloitte notice or filing in the material available for this article specifies:
- how many individuals were affected;
- which files were accessed or exfiltrated;
- the categories of personal information involved;
- whether Deloitte client data was included;
- whether Deloitte paid an extortion demand;
- whether a regulator brought an enforcement action; or
- whether Deloitte reached a settlement tied specifically to this incident.
Those gaps are important. Professional-services firms routinely process information for clients, so an affected file-transfer environment can expose third-party data without representing a compromise of the firm’s entire enterprise.
What is known about PwC
Available coverage says PwC confirmed that it was affected by the MOVEit vulnerability while describing the impact on the firm or its clients as limited. That supports reporting PwC as an affected organization, but not assigning it a mass-record total or claiming that a broad set of customer files was stolen.
As with Deloitte, the exact scope depends on the particular MOVEit environment, the files stored there and any later investigation or notice. A delayed notification can reflect the time needed to determine which records were involved; it does not by itself establish when an intrusion began.
Rank #3
What the EY–Bank of America settlement covers
The settlement website says EY used MOVEit in the ordinary course of business to handle certain Bank of America data. It identifies personally identifiable information belonging to some Bank of America customers and places the incident between May 27 and May 31, 2023.
The proposed agreement resolves claims against EY and Bank of America in that particular action. It does not resolve claims against Progress, and it should not be treated as a universal settlement for everyone who received a MOVEit-related notice. The settlement’s final-approval hearing is scheduled for October 15, 2026. The administrator lists October 8, 2026 as the claim deadline; instructions are available at the claims-filing page.
Recommended Free Tools
Why “victim” does not mean legal liability
“Victim” is shorthand for an organization affected by exploitation. It does not establish negligence, failure to patch, legal responsibility, identity theft, or a court finding against the organization. Liability questions depend on the facts and the claims in a particular case.
Rank #4
Progress’s filings describe ongoing litigation and say the company cannot yet reasonably estimate potential losses, judgments, settlements, fines or penalties. A dismissal of a claim may concern pleading, standing, causation or another legal issue; it does not mean the underlying MOVEit incident did not occur or that every claim against every defendant has ended.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Where the litigation stands in 2026
Progress reports that the federal cases are centralized in multidistrict litigation in the U.S. District Court for the District of Massachusetts. Its filing for the quarter ended May 31, 2026 states that:
- dismissal rulings occurred in 2025 and January 2026;
- 23 of 33 claims asserted by bellwether plaintiffs had been dismissed in whole or in part;
- fact discovery was scheduled to conclude on September 29, 2026;
- class-certification briefing was scheduled to begin on August 28, 2026; and
- the company did not expect the MDL to conclude within the following 12 months.
The filing is available through the Securities and Exchange Commission. Key MDL orders, including July 31, 2025 dismissal rulings and early-2026 orders on reconsideration and standing, are recorded at GovInfo.
Best Value
What affected individuals should do
- Read the exact notice. Identify the organization named as the sender or data custodian, the incident dates and the information categories listed.
- Match the case to the notice. Receiving a MOVEit notice from another company does not automatically make you eligible for the EY–Bank of America settlement.
- Use only the named administrator. File through the settlement or notification website identified in your notice, not an unrelated search result.
- Follow the notice’s protection instructions. If credit monitoring, fraud assistance or account changes are offered, use the enrollment instructions and deadlines supplied there.
- Watch for misuse. Be cautious with unexpected account, tax, payroll or password-reset messages, particularly if the notice says government identifiers or financial information were involved.
What remains unanswered
Publicly available reporting supports Deloitte’s inclusion in the MOVEit campaign and a minimal-impact characterization, but it does not provide a verified Deloitte record count or detailed data inventory. PwC’s public description is similarly limited. EY’s proposed settlement supplies a concrete Bank of America-related context, while leaving separate EY environments and other client relationships outside that agreement.
The most accurate conclusion is therefore specific, not sweeping: Deloitte, PwC and EY were all caught up in the MOVEit exploitation, but their publicly described exposure was not identical. Technical impact, the ownership of affected data, and legal responsibility must be evaluated separately for each notice and proceeding.
Frequently Asked Questions
Was KPMG part of this specific Big Four MOVEit grouping?
The sources used here identify Deloitte, PwC and EY. They do not establish KPMG as part of this specific grouping.
Does a MOVEit notice prove that my identity was stolen?
No. A notice indicates that information may have been accessed or exposed; it does not by itself prove identity theft. Follow the notice’s monitoring and fraud-prevention instructions.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




