← Progress Software (MOVEit)

2023 MOVEit SQL injection (CVE-2023-34362) — 62M+

2023 62.0M records affected Share on X

Data compromised

Names, SSNs, addresses, dates of birth, health records, financial data (varies by MOVEit customer)

Technical writeup

SQL injection zero-day (CVE-2023-34362) exploited by CL0P ransomware group. Global impact across MOVEit Transfer customers.

Root cause

SQL injection zero-day in MOVEit Transfer; CL0P ransomware exploitation.

References