MOVEit Transfer, 2023: one vendor's zero-day, many organisations' breach.
A ransomware group exploited an unknown SQL injection flaw in a widely used managed file transfer product, stealing data from organisations that had done nothing wrong except run it. What Progress Software disclosed and what CISA and the FBI advised.
Last updated Published by TryTrustableNot legal advice
From 27 May 2023 the Cl0p ransomware group exploited a zero-day SQL injection vulnerability (CVE-2023-34362) in Progress Software's MOVEit Transfer, installing a web shell called LEMURLOOT and stealing data from the databases behind internet-facing MOVEit servers. Progress was alerted by a customer on 28 May, notified all MOVEit customers on 30 May and released a patch on 31 May. CISA and the FBI published advisory AA23-158A on 7 June 2023. The breach reached many organisations through one third-party product.
What happened
| Date | What happened |
|---|---|
| 27 May 2023 | Cl0p begins exploiting the MOVEit Transfer vulnerability (CISA and FBI). |
| 28 May 2023, evening | Progress's MOVEit support team receives a customer call about unusual activity and discovers a zero-day vulnerability (Progress 8-K). |
| 30 May 2023 | Progress contacts all MOVEit Transfer and MOVEit Cloud customers with remedial steps and takes MOVEit Cloud down for investigation. |
| 31 May 2023 | A patch for all supported versions is released, and MOVEit Cloud is restored. |
| 2 June 2023 | CVE-2023-34362 is published in the National Vulnerability Database. |
| 7 June 2023 | CISA and the FBI publish advisory AA23-158A. |
| 6 August 2024 | The SEC tells Progress it has concluded its investigation and does not intend to recommend enforcement action. |
Root cause
The NVD entry for CVE-2023-34362 describes a SQL injection vulnerability in the MOVEit Transfer web application that could let an unauthenticated attacker gain access to its database. It was a zero-day: exploited before the vendor knew about it, so there was no patch to apply when the campaign began.
The CISA and FBI advisory AA23-158A attributes the campaign to CL0P (also known as TA505) and describes the LEMURLOOT web shell, written to target MOVEit Transfer and used to steal data from the underlying databases. The group used the stolen data for extortion.
The root cause for most victims was not something they configured. It was a third-party product exposed to the internet and holding sensitive files. That is why this case is about supplier risk, exposure and response speed more than about any one organisation's patching: the window between exploitation and a patch was days, and organisations that did not know they ran MOVEit, or where, lost time.
Impact and regulatory outcome
- Reach: the campaign affected many organisations, often through their own service providers. CISA's advisory gives estimates for TA505's activity in general, not a count for this campaign, so no figure is given here.
- Vendor disclosure: Progress described the discovery and its response in a Form 8-K filed in June 2023.
- SEC: Progress received an SEC subpoena on 2 October 2023; on 6 August 2024 the SEC told the company it had concluded its investigation and did not intend to recommend an enforcement action.
- Advice: AA23-158A recommends, among other things, prioritising the patching of known exploited vulnerabilities, phishing-resistant MFA, network segmentation, auditing administrative accounts with least privilege, and offline backups with a recovery plan.
The controls that address it
| Control | SOC 2 criteria | ISO 27001:2022 Annex A |
|---|---|---|
| Supplier inventory: which third-party products you run and what data they hold | CC9.2 | A.5.19, A.5.21, A.5.22 |
| Inventory of internet-facing assets | CC6.6, CC7.1 | A.5.9 |
| Emergency patching of known exploited vulnerabilities | CC7.1 | A.8.8 |
| Logging and monitoring of systems that hold sensitive files | CC7.2 | A.8.15, A.8.16 |
| Incident response, including notification of affected customers and regulators | CC7.3, CC7.4, CC2.3 | A.5.24, A.5.26 |
| Data minimisation and retention on file transfer systems | C1.2, P4.2 | A.8.10 |
SOC 2 references are the 2017 Trust Services Criteria (points of focus revised 2022); Annex A references are ISO/IEC 27001:2022. These are the usual mappings: agree yours with your auditor.
How TryTrustable checks these controls
- Knowing what is exposed: attack surface monitoring discovers your subdomains from Certificate Transparency logs, so internet-facing hosts you have forgotten show up, and flags expiring or expired certificates.
- Knowing your suppliers: the vendor register records each supplier, what it processes and its review date. Your team maintains the entries; there is no automated vendor scoring or monitoring.
- Testing your own applications:
trytrustable dastruns OWASP ZAP and Nuclei against your applications, and the SDK's static analysis runs in CI. Neither can find an unknown flaw inside someone else's product. - Responding: the incident management module records the timeline and regulatory deadlines, and the breach notification deadline calculator works out the reporting clocks for India and the GDPR.
- Logs to investigate with: AWS CloudTrail multi-region logging and GCP Data Access audit logs and log retention.
These are the checks TryTrustable runs today. None of them is a claim about what would have happened in this incident: they test whether the control is in place in your environment, continuously, and record the result as audit evidence.
Sources
- CISA and FBI advisory AA23-158A: #StopRansomware: CL0P ransomware gang exploits CVE-2023-34362 MOVEit vulnerability (7 June 2023)
- NIST National Vulnerability Database: CVE-2023-34362
- Progress Software Corporation, Form 8-K (event of 30 May 2023)
- Progress Software Corporation, Form 8-K of 7 August 2024: SEC investigation concluded
Every figure on this page is taken from the official documents listed here, read in October 2026. Regulatory findings quoted are the regulator's; where a company neither admitted nor denied them, or where proceedings are still open, the page says so. Not legal advice.
More case studies: all breach case studies · Research
The things people ask us
What was the MOVEit vulnerability?
CVE-2023-34362, a SQL injection vulnerability in the MOVEit Transfer web application that could let an unauthenticated attacker access its database. It was exploited as a zero-day from 27 May 2023, before a patch existed.
Who exploited MOVEit Transfer?
CISA and the FBI attribute the campaign to the CL0P ransomware gang, also known as TA505, which installed a web shell called LEMURLOOT and stole data for extortion.
How quickly did Progress release a patch?
Progress says it learned of unusual activity on the evening of 28 May 2023, notified all MOVEit customers on 30 May and released a patch for all supported versions on 31 May.
How do you manage the risk of a zero-day in a vendor's product?
Know which third-party products you run, where they face the internet and what data they hold, keep logs that let you investigate, and have an incident process that can move within hours of an advisory.
Check these controls in your own environment.
We connect GitHub and one cloud account in a demo and show which of these checks pass, with the evidence an auditor would ask for.