← Alight Solutions

2023 Alight Solutions — MOVEit Transfer zero-day (CVE-2023-34362); Cl0p mass-exfiltration campaign

2023 Unknown records affected Share on X

Data compromised

Varies by impacted employer programs—names, contact data, DOB, SSN, compensation/employment metadata cited in downstream legal summaries

Technical writeup

Benefits-administration provider Alight Solutions was among thousands of organizations caught in the May–June 2023 MOVEit Transfer supply-chain crisis, where the Cl0p / FIN11 ecosystem exploited CVE-2023-34362 (and follow-on MOVEit flaws) to raid internet-facing file-transfer appliances. Downstream regulatory and litigation summaries—e.g., Accelya breach letters summarized on JD Supra—describe Alight as the managed-file-transfer operator from whose MOVEit environment Accelya-bound HR/payroll-class files were stolen, prompting multi-party victim notification cascades. Use organization-specific record counts from filed notices when available; this row documents confirmed MOVEit victim status via the downstream disclosure chain and federal advisories.

Root cause

Zero-day SQLi / web-shell deployment against MOVEit Transfer permitting bulk data theft (per CISA/FBI guidance)

References