Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Managed File Transfer — The Forgotten Crown Jewel

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2023, written in 2026 with the benefit of hindsight.

The short version: In 2023, a ransomware gang exploited a flaw in MOVEit, a file transfer product, stealing data from over 2,000 organizations — many of which didn't know their vendors used it. File transfer systems quietly hold some of a company's most sensitive data.

Why file transfer systems are crown jewels

Payroll files, benefits data, customer records and financial reports pass through file transfer tools. These systems face the internet by design, often keep files longer than needed, and get less attention than email or ERP systems.

The business impact

  • Mass data theft and public extortion.
  • Notification obligations for data you held for others.
  • Third-party exposure through vendors using the same tool.

Questions to ask your team

  • Which file transfer tools do we run, and are they internet-facing?
  • How long do files stay on them?
  • Which of our vendors (payroll, benefits, banks) use file transfer tools to exchange our data?
  • How quickly did we act when MOVEit was announced?

What good looks like

A known list of file transfer systems, short file retention, emergency patching, restricted access, and vendor reviews that include how they exchange your data.

The decision

Ask for files on transfer platforms to be deleted after a short period — days, not months. Data that isn't there can't be stolen.

moveit breach impactMOVEit2023

More on this story