Case file · MOVEIT 2023

How the MOVEit hack happened: one file-transfer flaw, 60 million people

Published 2026-09-29 · 5 min read · Missing control: Purge data from file-transfer servers

The 2023 MOVEit attacks hit more than 1,000 organizations and more than 60 million people, and the gang behind them did not lock a single file. They copied what was sitting on file-transfer servers and threatened to publish it.[1][2] This case file covers how one flaw in a widely used file-sharing product became one of the largest data thefts on record, what it cost, and the control that would have left the thieves far less to take.

What happened

MOVEit Transfer, made by Progress Software, is a managed file transfer product. Organizations use it to send large or sensitive files to partners, such as payroll records, benefits data and customer lists, instead of emailing them.[3] Starting on May 27, 2023, the Memorial Day weekend in the US, a criminal group known as Clop began exploiting a previously unknown flaw in the product, tracked as CVE-2023-34362.[1][3]

Progress warned customers on May 31 and released fixes. Researchers counted about 2,500 MOVEit servers exposed to the internet, most of them in the US.[3] On June 5 the gang claimed responsibility, and instead of emailing ransom notes it told victims to contact it and set June 14 as the date it would start publishing stolen data.[4] CISA and the FBI issued a joint warning about the campaign on June 7.[1]

The first public victims included a UK payroll provider and airlines whose staff data passed through it.[4] The list kept growing all summer. By late August, more than 1,000 organizations had been confirmed as victims, with about 84% in the US.[2]

How they got in

The flaw let an outsider send specially crafted requests to a MOVEit server over the internet and trick it into running the attacker's commands, with no password needed.[1][3] The attackers then planted a hidden web page, disguised to look like part of the normal software, that worked as a back door. Through it they could read the server's database, list the files stored there and download them.[1][3]

Because the flaw was unknown until the attacks began, patching could not have stopped the first wave. What decided the damage was what each server held. Files that had been sent months earlier and never cleared out were just as easy to steal as the day's transfers.[3] The attackers did not need to encrypt anything to get paid. Federal agencies noted that since 2021 this group had leaned mostly on stealing data rather than locking it.[1]

What it cost

By August 25, 2023, a count of disclosures showed about 60 million people affected.[2] The largest single victims included the government contractor Maximus with about 11 million people, France's unemployment agency with about 10 million, and Louisiana's Office of Motor Vehicles with about 6 million.[2] Colorado's Medicaid agency and Oregon's Department of Transportation each reported millions more.[2]

One incident response firm estimated Clop could earn about $100 million from ransom payments. One analysis, based on an average cost per breached record, put the total cost of the breaches at close to $10 billion.[2] The US State Department offered a reward of up to $10 million for information on Clop.[2] The group is known for extortion that threatens to publish stolen data, and US agencies estimate it has hit thousands of organizations worldwide since 2019.[1]

The missing control

The missing control: purging data from file-transfer servers. A file-transfer system is a loading dock, not a warehouse. Files should be deleted automatically once the recipient has picked them up, or after a short set period.

No organization could have patched a flaw that no one knew about. But every organization decided how long files sat on its MOVEit server. Where files were cleared within days, the attackers found little to take. Where years of payroll, benefits and customer files were kept, they found everything.[2][3] Short retention does not stop the break-in; it limits what a break-in is worth. Keeping internet-facing servers patched and watched is the other half of the job, and the government advisory stressed both.[1]

What to do in your business

Watch the case
One file-transfer flaw, 60 million people's data stolenDrops 2027-01-04
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. CISA and FBI: #StopRansomware, CL0P ransomware gang exploits CVE-2023-34362 MOVEit vulnerability (AA23-158A)
  2. TechCrunch: MOVEit mass hack by the numbers
  3. BleepingComputer: New MOVEit Transfer zero-day mass exploited in data theft attacks
  4. BleepingComputer: Clop ransomware claims responsibility for MOVEit extortion attacks