Which 2023 cyberattack exploited a vulnerability in Progress Software’s MOVEit Transfer file-sharing platform?
Answer
The MOVEit data breach
Answer
The MOVEit data breach
The 2023 cyberattack that exploited a vulnerability in Progress Software’s MOVEit Transfer platform was the MOVEit data breach.
The MOVEit data breach involved the exploitation of a SQL-injection vulnerability in MOVEit Transfer, a managed file-transfer product used by organizations to exchange sensitive files. The vulnerability was assigned CVE-2023-34362 and was publicly disclosed by Progress Software in May 2023.
The Clop ransomware and extortion group, also known as TA505 in some reporting contexts, exploited the flaw to access data from vulnerable servers. Instead of encrypting every victim’s systems, the campaign focused heavily on stealing files and demanding payment or threatening publication.
Because MOVEit servers were used by service providers and organizations that held data for others, the impact spread through supply-chain relationships. Reported victims included public agencies, universities, pension administrators, and companies. The incident is distinct from the SolarWinds attack, which involved a compromised software update rather than a vulnerability in a file-transfer product.
Source: Wikipedia · fact-checked Sept. 2026