2023 FIS — MOVEit Transfer zero-day wave (Cl0p); downstream client-file exposure
Data compromised
Client and customer PII in transferred files per state-filed notification excerpts summarized in trade and legal press
Technical writeup
Fidelity National Information Services (FIS) appeared on state breach indices alongside the global Progress MOVEit Transfer compromise attributed to the Cl0p criminal cluster, with public regulatory samples describing unauthorized access to files transited through impacted MOVEit instances and downstream customer notice obligations (e.g., banking-sector clients citing names and Social Security numbers in shared letter mirrors). Third-party and legal summaries cited large six-figure notification populations for FIS’s MOVEit filing wave without a single regulator-normalized global integer in BreachHistory’s pass.
Root cause
Critical vulnerability exploitation in third-party managed file transfer (MOVEit) leveraged at scale by Cl0p