Attack path
Exploitation of a SQL-injection flaw in internet-facing MOVEit Transfer instances to steal data.
Confirmed impact
Multiple organizations faced data theft and extortion; impact varies by each official disclosure.
Response
Temporary HTTP/HTTPS shutdown, Progress patching, indicator hunting and account and file review.
