Fortescue Metals disclosed that it was affected by the mass exploitation of Progress Software's MOVEit Transfer platform, joining a growing list of organizations whose data was exposed through the third-party file transfer breach. The incident highlighted how attackers leveraged a zero-day in MOVEit Transfer to steal information from enterprises that relied on the service for secure data exchange, extending the impact beyond direct victims to their customers, employees, and business partners.
Rogers and Freedom Mobile also reported separate recent data breaches tied to external suppliers, underscoring the continued risk posed by vendor compromises across critical industries. The telecom companies said customer information was exposed through third-party incidents rather than intrusions into their core networks, reinforcing a broader pattern in which attackers target service providers and software platforms to gain access to data held by major enterprises.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
A March 2026 report stated that Rogers and Freedom Mobile had experienced data breaches in recent weeks. The reference indicates disclosure by the telecom companies but provides no more precise breach dates in the supplied content.
A July 2023 report identified Australian iron ore company Fortescue Metals as among the organizations affected by the MOVEit Transfer mass exploitation campaign. The reference does not provide a more specific incident date than the publication timeframe.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
theglobeandmail.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.