The Cl0p extortion group exploited multiple critical SQL injection flaws in Progress Software's MOVEit Transfer platform, beginning with the zero-day later tracked as CVE-2023-34362, to breach organizations worldwide and steal large volumes of data. Researchers and government agencies linked the campaign to Cl0p, also tracked as Lace Tempest, FIN11, and TA505, and reported that attackers often deployed the LemurLoot web shell and exfiltrated files within minutes; in some cases, the malware could also pull Azure Blob storage details and credentials from MOVEit settings. Progress disclosed and patched additional MOVEit vulnerabilities, including CVE-2023-35036 and CVE-2023-35708, as incident responders warned that victim counts would continue to rise through delayed breach notifications and downstream third-party exposure.
The fallout spread across government, finance, healthcare, education, insurance, professional services, and major global brands, with disclosures naming entities such as EY, PwC, Sony and Pan-American Life Insurance Group among the affected organizations or reported victims. By later tallies, the campaign had compromised thousands of organizations and tens of millions of individuals, while Cl0p shifted from encryption to data-theft and extortion, publishing stolen information from nonpaying victims on leak sites. The incident triggered broad regulatory scrutiny, lawsuits, response costs, and supply-chain consequences as organizations discovered that exposure often came through vendors and file-transfer partners rather than direct compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
62 events from the most recent confirmed update back to the earliest known activity.
Greater Rochester Independent Practice Association agreed to settle litigation stemming from the May 2023 MOVEit breach, creating a $2.15 million fund and offering cash payments, reimbursement, and two years of credit monitoring and identity theft protection. The proposed settlement received preliminary court approval, with claims due by 2026-09-03 and objections or exclusions due by 2026-08-04.
As of 2024-06-28, Emsisoft's tracking put the MOVEit campaign at 2,773 organizations and 95,788,491 affected individuals. U.S.-based entities made up most known victims, with education, healthcare, and finance/professional services among the hardest-hit sectors.
Pan-American Life Insurance Group disclosed a data breach affecting about 105,000 individuals that was tied to the MOVEit incident. The disclosure illustrated the long tail of victim notifications months after the initial exploitation.
Aetna Life Insurance Company disclosed that a MOVEit Transfer-related breach impacted more than 300,000 individuals. The notice added another major insurance-sector victim to the long tail of breach disclosures tied to Cl0p's mass exploitation campaign.
Blue Shield of California disclosed that a MOVEit-related breach affected hundreds of thousands of members. The notice added another major healthcare insurer to the continuing stream of downstream victim disclosures tied to the Cl0p MOVEit exploitation campaign.
The Medical College of Wisconsin said a MOVEit Transfer-related breach affected more than 240,000 individuals. The disclosure added another healthcare-sector victim to the long tail of organizations reporting impact from the Cl0p exploitation campaign.
Welltok was reported as a victim of the MOVEit Transfer mass exploitation campaign, with the breach affecting roughly 1.6 million individuals. The disclosure added another major healthcare-sector downstream victim to the continuing stream of breach notifications tied to Cl0p's attacks.
California-based MESVision said a MOVEit Transfer-related breach impacted close to 350,000 patients. The disclosure added another healthcare-sector victim to the continuing stream of downstream breach notifications tied to the Cl0p MOVEit exploitation campaign.
Maine state government disclosed that a MOVEit-related data breach impacted roughly 1.3 million residents. The notice added a major U.S. state-government victim and one of the larger publicly reported population-level exposures tied to the Cl0p MOVEit campaign.
Westat, Inc. disclosed a data breach resulting from exploitation of the MOVEit software vulnerability. The notice added another downstream victim to the long tail of organizations publicly reporting impact from the Cl0p MOVEit campaign.
SC Media reported that Sutter Health disclosed a MOVEit-linked data breach affecting more than 845,000 patients. The notice added another major healthcare-sector victim to the long tail of downstream breach disclosures tied to Cl0p's mass exploitation campaign.
Sun Life Financial disclosed that a MOVEit-related data breach impacted more than 212,000 U.S. customers. The notice added another insurance-sector victim to the continuing stream of downstream breach disclosures tied to the Cl0p MOVEit exploitation campaign.
Healthcare technology company NASCO was reported as a victim of the MOVEit Transfer mass exploitation campaign, with data exposure affecting roughly 800,000 individuals. The disclosure added another major downstream victim to the long-running stream of breach notifications tied to Cl0p's attacks.
CCleaner confirmed that it was affected by the MOVEit mass exploitation campaign, adding another named software company to the list of publicly disclosed victims tied to Cl0p's attacks. The disclosure extended the campaign's known impact into the consumer software sector.
By October 2023, reporting cited more than 2,550 affected organizations and roughly 66 million impacted individuals. The incident had also triggered major financial, legal, and regulatory consequences for Progress, including lawsuits and an SEC inquiry.
A Texas-based credit union disclosed that a MOVEit Transfer-related data breach impacted about 102,000 customers. The notice added another financial-sector victim to the long tail of downstream breach disclosures tied to Cl0p's mass exploitation campaign.
Later in August, Cl0p released more data from MOVEit victims, continuing the extortion campaign and increasing the exposure of stolen records. The leaks underscored that many affected organizations had not reached agreements with the attackers.
Reporting on 2023-08-25 said data belonging to more than 300,000 Standard Insurance customers was exposed through NTT DATA's MOVEit-related breach. The disclosure added another downstream victim relationship to the expanding impact of the Cl0p MOVEit exploitation campaign.
In August 2023, Cl0p started publishing data stolen in the MOVEit campaign, escalating pressure on victims through extortion. Public leaks marked a shift from claims of compromise to visible release of exfiltrated information.
U.S. government contractor Serco publicly disclosed a data breach resulting from the MOVEit mass exploitation campaign. The disclosure added another notable downstream victim connected to sensitive government-related services.
On 2023-07-31, the Centers for Medicare & Medicaid Services disclosed that a MOVEit-linked breach exposed personal data belonging to about 612,000 Medicare beneficiaries. The notice added a major U.S. government healthcare impact disclosure to the expanding list of downstream victims tied to the Cl0p campaign.
A Medicaid administrator disclosed a MOVEit-linked breach affecting more than 8 million people. The report marked a major escalation in downstream impact, adding one of the largest publicly reported exposure totals tied to the Cl0p MOVEit campaign at that time.
Reporting on 2023-07-27 said government services contractor Maximus and consultant Deloitte were among organizations affected by the MOVEit exploitation campaign. The disclosure highlighted exposure of healthcare-related files affecting millions of people, adding major named victims to the incident's growing toll.
On 2023-07-21, reporting said DHL was investigating whether it had been affected by the MOVEit Transfer exploitation campaign. The report added a major global logistics brand to the list of organizations publicly responding to possible compromise tied to Cl0p's attacks.
On 2023-07-20, UK telecom regulator Ofcom said it was affected by the MOVEit Transfer mass exploitation campaign and stated it would not pay a ransom demand. The report also identified Ireland's telecom regulator ComReg as another newly disclosed victim, adding European regulators to the growing list of impacted organizations.
A 2023-07-19 report said cosmetics companies Estée Lauder and Mary Kay were on the growing list of organizations affected by the Cl0p MOVEit Transfer exploitation campaign. The disclosure added newly named consumer-brand victims to the expanding roster of impacted companies.
Reporting on 2023-07-17 said TJ Maxx and TomTom were among the latest organizations to confirm data incidents tied to the Cl0p MOVEit Transfer exploitation campaign. The disclosures added major retail and navigation-technology brands to the growing list of publicly identified victims.
TechMonitor reported that Vitesco Technologies was among the organizations identified as victims of the Cl0p MOVEit Transfer exploitation campaign. The report added another named enterprise victim to the expanding list of affected companies.
Colorado State University said a data breach tied to the MOVEit Transfer exploitation campaign affected students and staff. The disclosure added another higher-education victim to the growing list of organizations impacted by Cl0p's mass exploitation.
Shutterfly said it was affected by the Cl0p-linked MOVEit campaign but stated that its investigation found no impact to customer data. The statement added a new named victim response and clarified the scope of exposure at the company.
By mid-July, incident tracking showed the mass exploitation had spread to hundreds of organizations and many downstream third parties. Government, healthcare, education, finance, pensions, and manufacturing were among the affected sectors.
On 2023-07-12, reporting said healthcare organization PBI suffered a MOVEit-linked data breach exposing details of more than 370,000 people. The disclosure added another healthcare-sector victim to the growing list of organizations impacted by Cl0p's mass exploitation campaign.
Becker's Hospital Review reported that another health system had become a disclosed victim of the MOVEit Transfer mass exploitation campaign. The report added a new healthcare-sector victim to the growing list of organizations publicly acknowledging impact from Cl0p's attacks.
On 2023-07-10, reporting said Choice Hotels disclosed that guest information from Radisson Hotels Americas was exposed through the MOVEit Transfer attacks. The report added a major hospitality-sector victim relationship to the growing list of downstream organizations affected by the Cl0p exploitation campaign.
A 2023-07-10 report said Deutsche Bank and its Postbank unit were affected by the Cl0p MOVEit Transfer exploitation campaign, exposing customer data. The disclosure added a major European banking-sector victim to the growing list of publicly identified organizations tied to the mass exploitation.
On 2023-07-07, CISA warned about three newly disclosed MOVEit Transfer vulnerabilities as additional organizations continued reporting breaches tied to the broader exploitation wave. The alert marked a further technical escalation beyond the earlier June patches, indicating more flaws had been identified in the product.
Ciena disclosed that it was affected by the MOVEit Transfer attack and said the incident had a limited impact on data. The statement added another named enterprise victim to the growing list of organizations publicly acknowledging exposure tied to the Cl0p campaign.
On 2023-06-30, reporting said schools disclosed that TIAA, a major U.S. retirement fund serving teachers and academic institutions, was targeted in the MOVEit hacking campaign. The report added another major financial and education-linked victim relationship to the growing list of organizations affected by Cl0p's mass exploitation.
Reporting on 2023-06-29 said Honeywell had been compromised in the MOVEit Transfer hacking campaign. The disclosure added a major industrial and technology company to the growing list of organizations publicly identified as affected by Cl0p's mass exploitation.
On 2023-06-29, CNN reported that the U.S. Department of Health and Human Services was affected by the MOVEit cyberattack and said at least 100,000 people could have had their data exposed. The disclosure added a major U.S. federal health-sector victim to the growing list of organizations impacted by Cl0p's mass exploitation campaign.
Reporting on 2023-06-27 said UCLA and Siemens Energy had confirmed breaches tied to the MOVEit Transfer exploitation campaign. The disclosures added a major U.S. university and a global energy technology company to the growing list of publicly identified victims.
On 2023-06-23, reporting said Cl0p had added GUS Canada to its list of organizations allegedly compromised in the MOVEit Transfer exploitation campaign. The claim expanded the roster of publicly named victims beyond those already reported such as PwC and Sony.
On 2023-06-22, reporting said the California Public Employees' Retirement System (CalPERS) was affected by the MOVEit Transfer exploitation campaign. The disclosure added a major U.S. public pension fund to the growing list of organizations impacted by the Cl0p-linked mass exploitation.
By 2023-06-22, reporting linked additional prominent organizations such as EY, PwC, and Sony to the expanding MOVEit victim list. This reflected the campaign's growing impact across major enterprises and service providers.
Telos confirmed that it suffered a data breach related to exploitation of the MOVEit Transfer vulnerability. The disclosure added another named enterprise and government-services contractor to the growing list of organizations affected by the Cl0p-linked mass exploitation campaign.
On 2023-06-20, Cl0p reportedly claimed it did not possess stolen data from the BBC, British Airways, or Boots, despite those organizations being linked to the MOVEit fallout through payroll provider Zellis. The statement added a notable attacker response about the scope of data theft affecting several high-profile UK organizations.
Transport for London disclosed that the MOVEit hack compromised data belonging to about 13,000 drivers. The announcement added a major UK transport-sector organization to the growing list of publicly identified victims tied to the Cl0p MOVEit exploitation campaign.
Federal News Network reported that the U.S. Department of Energy was among several federal agencies affected by the MOVEit Transfer exploitation campaign. The report added a specific set of federal-government victims to the growing list of organizations impacted by Cl0p's mass exploitation.
On 2023-06-15, Progress patched another MOVEit Transfer flaw, CVE-2023-35708. The additional remediation showed that the incident involved multiple serious vulnerabilities, not just the original zero-day.
A 2023-06-12 report said Illinois was affected by the wide-ranging MOVEit/Cl0p attack, adding another U.S. state government victim to the growing list of publicly identified organizations. The disclosure further showed the campaign's expanding impact on public-sector entities.
Progress released fixes for a second MOVEit Transfer vulnerability, CVE-2023-35036, as investigators uncovered additional security issues during response efforts. The patch was part of an ongoing effort to contain the exploitation campaign.
CBS reported that the Minnesota Department of Education was hit in the global MOVEit cyberattack, exposing data on about 95,000 students. The disclosure added a new public-sector victim to the growing list of organizations affected by the mass exploitation campaign.
Nova Scotia Health disclosed that the MOVEit-related breach affected about 100,000 individuals. The notice adds a quantified healthcare-sector impact disclosure tied to the long tail of downstream victim notifications from the Cl0p MOVEit campaign.
By 2023-06-08, organizations were publicly disclosing data breaches tied to the MOVEit flaw as the victim count began to rise. Reporting indicated the incident was expanding beyond direct users to downstream organizations whose data was handled by affected third parties.
On 2023-06-07, the Russian-speaking Cl0p gang claimed responsibility for breaches affecting BBC and British Airways employee data via payroll provider Zellis. The group said it had data from hundreds of companies and warned victims to negotiate by June 14 before stolen information would be published.
Reporting on 2023-06-06 identified the University of Rochester and the government of Nova Scotia as among the first known North American organizations affected by the MOVEit Transfer exploitation campaign. The disclosure added specific early victims to the emerging list of organizations impacted by Cl0p's mass exploitation.
By early June, Rapid7 and other researchers described the MOVEit activity as a widespread threat affecting high-value targets across sectors, sizes, and geographies. Independent tracking already showed a double-digit number of organizations with stolen data, including U.S. government and banking entities.
On 2023-06-05, BBC reporting identified the BBC, British Airways, and Boots as among the organizations affected by the MOVEit cyberattack through payroll provider Zellis. The report added several high-profile UK brands to the early list of victims tied to the expanding exploitation campaign.
On 2023-05-31, Progress Software disclosed an actively exploited SQL injection vulnerability in MOVEit Transfer, later tracked as CVE-2023-34362 with a CVSS score of 9.8. The company released fixes and urged customers to take immediate mitigation steps.
A MOVEit customer observed suspicious activity during the U.S. Memorial Day weekend, helping surface the broader compromise. This activity preceded public disclosure and indicated active exploitation in the wild.
Mandiant reported that the Cl0p extortion operation began exploiting a SQL injection zero-day in MOVEit Transfer on 2023-05-27. Attackers used the LemurLoot webshell and in some cases stole data within minutes, including potentially Azure Blob storage credentials from compromised systems.
By May 2026, reporting indicated the data breach toll tied to Cl0p's MOVEit attacks had continued to rise beyond earlier counts. This reflected the prolonged disclosure cycle and ongoing identification of affected organizations and individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourceintel471.com
Open sourcehipaajournal.com
Open sourceteiss.co.uk
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourcegbhackers.com
Open sourcecnn.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.