2023 Zellis — MOVEit Transfer (CVE-2023-34362); payroll supply-chain to BA, BBC, Boots, Aer Lingus, DHL cohorts
Data compromised
Payroll PII for employees of notified clients—fields vary by notice
Technical writeup
UK payroll and HR technology provider Zellis was swept into the global May–June 2023 MOVEit Transfer mass-exploitation campaign attributed to CL0P / Lace Tempest. Press and class-action summaries described unauthorized access to a MOVEit instance processing payroll files for major employer clients, with downstream notifications covering large airline, retail, media, and logistics workforces. Data categories in public letters commonly included name, contact, National Insurance number–class identifiers, and banking elements for pay. Totals aggregate across client employers rather than a single Zellis user table.
Root cause
Zero-day SQL injection / web shell chain against internet-facing MOVEit Transfer (CISA AA23-158A ecosystem pattern)