
What happened
On 31 May 2023, Progress Software told customers about a critical flaw in its MOVEit Transfer managed file-transfer product. The CISA alert issued that week described the flaw as a SQL injection that could let an unauthenticated attacker take over an affected system. The National Vulnerability Database entry for CVE-2023-34362 records the underlying issue as unauthenticated access to the MOVEit database, with a critical severity rating. A joint advisory from the FBI and CISA, published a week later, attributed active exploitation to the Cl0p group, which it said had begun exploiting the flaw on 27 May, days before the public disclosure.
The joint advisory describes a distinct pattern. Rather than deploying ransomware that encrypts files and announces itself, the attackers installed a web shell the advisory calls LEMURLOOT, which could extract stored credentials, enumerate databases and create privileged accounts. That let the group copy data out of MOVEit instances quietly, then extort victims over the theft alone. The advisory reported that the group claimed roughly 130 victims within the first ten days, and it warned that government and private-sector customers alike should expect wider exploitation of unpatched instances.
Confidence and limits
The vulnerability's existence, mechanism and initial exploitation window are established by a government advisory and a vulnerability record, which is a strong basis. What is not established here is a final victim count: the advisory's 130-victim figure covers only the first ten days it describes, and the record does not support a single up-to-date total. Attribution to Cl0p rests on the advisory's own assessment rather than a court finding.
Why it mattered
Because the compromise was data theft rather than encryption, many victims found out only when a vendor they used for file transfer, payroll or benefits processing was itself named as a MOVEit customer. A single vulnerability in shared infrastructure therefore produced breach notifications from organisations that had never used MOVEit directly, and the disclosures continued for months as downstream customers worked out whether their data had passed through an affected instance.
Defensive takeaway
If your organisation relies on a managed file-transfer product, treat it as a high-value target rather than routine infrastructure: check patch status against the vendor's advisory promptly, and ask any third party that moves your data on your behalf whether it uses an affected product.
- Do you know which vendors and file-transfer tools touch data on your organisation's behalf, including ones several steps removed from you?
- Would your organisation detect data leaving through a legitimate application account rather than through an obvious malware alert?
- Is there a documented process for asking downstream vendors to confirm exposure when a widely used product discloses a critical flaw?
The MOVEit case is a reminder that a single vulnerability in software many organisations quietly depend on can produce a breach count that keeps rising long after the initial advisory, simply because supply chains are longer than any one victim can see.
Treat managed file-transfer software as high-value infrastructure, confirm patch status against the vendor's advisory promptly, and ask any third party that moves your data whether it runs an affected product.
The vulnerability, its exploitation window and the attacker's data-theft method are established by a government advisory and the NVD record. The total number of eventual victims is not established here, since the cited sources cover only the first weeks of exploitation.
Sources & reading trail
Confirms the critical SQL injection flaw and CISA's recommendation to review the vendor advisory, patch, and search for indicators of compromise.
government-primary · Source published: 1 June 2023 · Retrieved: 16 September 2026
Establishes the vulnerability's technical description as an unauthenticated SQL injection in MOVEit Transfer and its critical severity rating.
government-primary · Source published: 2 June 2023 · Retrieved: 16 September 2026
Attributes active exploitation to the Cl0p group beginning 27 May 2023 and describes the LEMURLOOT web shell used to steal data without encryption.
government-primary · Source published: 7 June 2023 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.