← FIS

2023 FIS — MOVEit Transfer zero-day wave (Cl0p); downstream client-file exposure

2023 Unknown records affected Share on X

Data compromised

Client and customer PII in transferred files per state-filed notification excerpts summarized in trade and legal press

Technical writeup

Fidelity National Information Services (FIS) appeared on state breach indices alongside the global Progress MOVEit Transfer compromise attributed to the Cl0p criminal cluster, with public regulatory samples describing unauthorized access to files transited through impacted MOVEit instances and downstream customer notice obligations (e.g., banking-sector clients citing names and Social Security numbers in shared letter mirrors). Third-party and legal summaries cited large six-figure notification populations for FIS’s MOVEit filing wave without a single regulator-normalized global integer in BreachHistory’s pass.

Root cause

Critical vulnerability exploitation in third-party managed file transfer (MOVEit) leveraged at scale by Cl0p

References