Back to the archive
Incident file · 2023
MOVEit customers (Progress Software)
Software supply chain · United States · Threat actor: Cl0p
Supply chain
Ransom refused
- Undisclosed
- Ransom demanded
- No
- Ransom paid
- 5 days
- Estimated downtime
- US$210m
- Est. revenue lost
What happened
A zero-day SQL injection flaw in the MOVEit managed file transfer product was mass-exploited to steal customer data downstream.
How it ended
Most victims refused to pay; Cl0p published data in batches, driving global notification and litigation costs.
Data affected
2,700+ organisations, 95m+ people
Would your business survive this incident?
We stress-test detection, response and recovery so a ransom demand is never your only option.