EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/supply-chain-attack/moveit-transfer-cl0p-2023
134/430

File EL-0297CriticalResolvedSupply Chain Attack / Zero-Day Exploitation

MOVEit Transfer Cl0p Ransomware Mass Exploitation

Also filed as MOVEit Zero-Day Exploitation · CVE-2023-34362 Attack

This incident involved the mass exploitation of a zero-day SQL Injection vulnerability (CVE-2023-34362) in the MOVEit Transfer web application. The vulnerability allowed unauthorized remote access and data exfiltration from numerous global organizations. The attack highlighted the critical risks inherent in third-party software supply chains.

  • #moveit
  • #cl0p
  • #sql-injection
  • #cve-2023-34362
  • #supply-chain
  • #ransomware
Notoriety9/10
Event
27 May 2023
Disclosed
31 May 2023
Target
MOVEit Transfer Users
Actor
Cl0p Ransomware Group
Scale
Massive (Millions of records across 2,000+ organizations)
Status
Resolved

01Summary

The Cl0p Ransomware Group exploited a critical SQL Injection vulnerability in the MOVEit Transfer platform, a widely used enterprise file transfer solution. This zero-day flaw allowed attackers to bypass authentication and execute arbitrary database commands, leading to the exfiltration of massive amounts of sensitive data. The attack was highly coordinated, targeting over 2,000 organizations globally, including major government bodies and multinational corporations. The leaked data included payroll records, driver's licenses, and confidential corporate information. The incident forced organizations worldwide to immediately patch or take the service offline, demonstrating the profound systemic risk posed by compromised third-party software.

02Background

MOVEit Transfer is a commercial file transfer solution utilized by thousands of organizations for secure data exchange. The reliance on such centralized, widely adopted software created a single point of failure, making it a prime target for sophisticated criminal groups. The vulnerability was exploited before the vendor could issue a patch, allowing the attackers to operate undetected for a period.

03Key revelations

  1. 01The vulnerability allowed attackers to bypass authentication and access sensitive databases.
  2. 02The attack demonstrated the systemic risk of relying on single, widely-used third-party software platforms.
  3. 03The sheer scale of the breach, affecting over 2,000 organizations globally, highlighted global supply chain fragility.

04Technical analysis

The vulnerability was classified as a SQL Injection (SQLi) flaw, specifically CVE-2023-34362. Attackers leveraged this flaw to manipulate the underlying database queries, enabling them to dump entire tables of data. The attack vector was remote and required no prior access, making it exceptionally dangerous. The exfiltration method involved systematically pulling data from the compromised database and staging it for sale or use in extortion.

Attack vector
Remote Web Exploitation (SQL Injection)
Attack method
Data Exfiltration and Extortion
Initial access
Exploitation of unpatched software vulnerability
Exfiltration
Database dumping and remote transfer
Tool / malware
MOVEit Transfer
Malware type
Exploit

Vulnerabilities exploited

  • CVE-2023-34362

MITRE ATT&CK techniques

  • T1566.001
  • T1190

05Threat actor

Cl0p is a highly organized and financially motivated ransomware group known for its sophisticated exploitation of zero-day vulnerabilities. They specialize in targeting large, complex organizations and often use double extortion tactics, threatening to leak data if a ransom is not paid.

Aliases

  • Cl0p
  • Clop

MITRE groups

  • T1566.001
  • T1190

Attribution sources

  • BBC
  • Mandiant
  • CISA

06Victims and impact

Additional victims

  • British Airways
  • BBC
  • US Dept of Energy
  • Shell
  • Siemens

Countries affected

  • United States
  • United Kingdom
  • Canada

07Data exposed

Data types

  • PII
  • Financial records
  • Credentials
  • Classified documents
  • Health records

Notable documents

  • Payroll data (British Airways)
  • Driver's licenses (Louisiana OMV)
  • Confidential corporate records (Shell, BBC)

08Financial damage

Estimated damage includes regulatory fines, operational downtime, and remediation costs.

09Timeline

  1. 2023-05-27Initial exploitation of the MOVEit Transfer vulnerability begins.
  2. 2023-05-31Cl0p Ransomware Group publicly announces the exploit and leaks data from multiple organizations.
  3. 2023-06-17MOVEit vendor releases comprehensive patches and security updates.

10On the record

This is the definition of a supply chain attack. One obscure software vendor falls, and the world bleeds.

Cl0p Ransomware Group, Statement accompanying the leak of exfiltrated data.

11Reaction and fallout

Public reaction

The public reaction was one of alarm regarding digital security, leading to increased scrutiny of enterprise software vendors. Governments and major corporations were forced to issue urgent security advisories and implement emergency patching protocols.

Political impact

The incident spurred immediate governmental reviews of critical infrastructure software supply chain security. It increased political pressure on software vendors to adopt 'security by design' principles and provide timely patch management.

Geopolitical consequences

The attack reinforced the concept of cyber warfare targeting civilian infrastructure, making software supply chain integrity a matter of national security concern across multiple allied nations.

12Legal

While no single legal outcome was immediate, the incident contributed to a global push for stricter data protection regulations and mandatory breach reporting, particularly in the EU and US.

Civil lawsuits

  • Class-action lawsuits filed by affected organizations seeking damages for data exposure.

13Aftermath

Policy changes

  • Increased mandatory third-party risk assessments for critical infrastructure.
  • Adoption of Software Bill of Materials (SBOM) requirements.

Regulatory changes

  • Enhanced enforcement of GDPR and CCPA regarding third-party data processing.
  • Mandatory reporting of supply chain vulnerabilities to national cybersecurity agencies.

Security improvements

  • Implementation of Web Application Firewalls (WAFs) specifically tuned for SQLi protection.
  • Adoption of least-privilege access models for all third-party integrations.
  • Mandatory network segmentation to isolate critical systems from external-facing services.

14Significance and legacy

Significance

This incident is a textbook example of a modern supply chain attack, demonstrating how a single, widely-used software vulnerability can compromise thousands of unrelated, high-value targets. It shifted the focus of cyber risk from endpoint security to the integrity of the software supply chain itself.

Legacy

The MOVEit breach accelerated the industry's focus on Software Supply Chain Security (SSCS). It led to increased adoption of SBOMs and prompted major regulatory bodies to treat third-party software risk with the same gravity as internal network risk.

15Disclosure and media

Authentication
Technical analysis of exploit code and vendor confirmation

Media partners

  • BBC
  • The New York Times
  • Reuters

Publishing organisations

  • BBC
  • Mandiant

16Related files

Related events

  • SolarWinds Supply Chain Attack

17Field notes

  1. 01The vulnerability was a classic SQL Injection flaw, which is considered one of the oldest and most common web application vulnerabilities.
  2. 02The attack demonstrated that even highly secure, regulated organizations (like government bodies) are vulnerable if they rely on unpatched third-party software.

18Resolution

The vulnerability was patched by the vendor, and affected organizations were advised to immediately update or decommission the service until patches were verified. The incident led to a temporary, but significant, global slowdown in data transfer operations for affected entities.

19Sources

Official documents

  • CISA Advisory on MOVEit Vulnerability
  • MOVEit Vendor Security Patches

References

  1. [1]BBC Security Reports
  2. [2]Mandiant Threat Intelligence
  3. [3]CISA Alerts
Fact sheetEL-0297

Dates

Event
27 May 2023
Started
27 May 2023
Ended
31 May 2023
Duration
21 days
Discovered
31 May 2023
Disclosed
31 May 2023
Resolved
17 Jun 2023
Ongoing
No

Target

Organisation
MOVEit Transfer Web Application
Type
Technology Company
Sector
Enterprise Software/Data Transfer
Country
Global
Gov. level
Federal, State, Local

Actor

Name
Cl0p Ransomware Group
Type
Ransomware Gang
Motivation
Financial gain through data exfiltration and ransom payment
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
Massive (Millions of records across 2,000+ organizations)
Sensitivity
Top Secret
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.