← Zellis

2023 Zellis — MOVEit Transfer (CVE-2023-34362); payroll supply-chain to BA, BBC, Boots, Aer Lingus, DHL cohorts

2023 Unknown records affected Share on X

Data compromised

Payroll PII for employees of notified clients—fields vary by notice

Technical writeup

UK payroll and HR technology provider Zellis was swept into the global May–June 2023 MOVEit Transfer mass-exploitation campaign attributed to CL0P / Lace Tempest. Press and class-action summaries described unauthorized access to a MOVEit instance processing payroll files for major employer clients, with downstream notifications covering large airline, retail, media, and logistics workforces. Data categories in public letters commonly included name, contact, National Insurance number–class identifiers, and banking elements for pay. Totals aggregate across client employers rather than a single Zellis user table.

Root cause

Zero-day SQL injection / web shell chain against internet-facing MOVEit Transfer (CISA AA23-158A ecosystem pattern)

References