← Paycor

2023 Paycor — MOVEit Transfer (CVE-2023-34362) compromise; CL0P

2023 Unknown records affected Share on X

Data compromised

Employer payroll files in MOVEit pipelines—commonly name, DOB, SSN in cited templates

Technical writeup

Paycor, a payroll and workforce HCM vendor, was swept into the global May–June 2023 MOVEit Transfer mass-exploitation campaign attributed to CL0P. Client notification letters (e.g., Neste US distributed via state attorney-general repositories, and Infotech notice in Maine records) stated that exploitation of CVE-2023-34362 against Paycor’s MOVEit instances could have exposed files in transit containing employee name, date of birth, and Social Security number-class data for downstream employer populations. Totals vary by employer notification cohort.

Root cause

Zero-day SQL injection / web-shell deployment against internet-facing MOVEit Transfer (CISA AA23-158A pattern)

References