INCIDENT FILE / 02

2023-05-31 · Multiple organizations / Global

MOVEit Transfer exploitation

Multiple organizations faced data theft and extortion; impact varies by each official disclosure.

01

Attack path

Exploitation of a SQL-injection flaw in internet-facing MOVEit Transfer instances to steal data.

02

Confirmed impact

Multiple organizations faced data theft and extortion; impact varies by each official disclosure.

03

Response

Temporary HTTP/HTTPS shutdown, Progress patching, indicator hunting and account and file review.