← AvidXchange, Inc.

2023 AvidXchange — Fortra GoAnywhere MFT compromise (supply chain to check-printing file flows)

2023 Unknown records affected Share on X

Data compromised

Transferred operational files in scoped MFT pipelines—categories not uniformly itemized in first press cycle

Technical writeup

AvidXchange confirmed use of Fortra’s GoAnywhere managed file transfer platform for flows to a third-party check-printing provider and was listed among organizations caught in the early-2023 GoAnywhere zero-day exploitation wave tied to the CL0P crimeware ecosystem. TechCrunch and peer coverage described the incident as distinct from a later in-house network intrusion disclosed the same year. Public summaries emphasized file-transfer abuse rather than full SaaS database exfiltration, with client-impact geometry clarified in subsequent Avid notifications.

Root cause

Exploitation of vulnerable GoAnywhere MFT instance (CVE-2023-0669 class incident era)

References