Multi-CloudIncident TeardownsRetrospectives

MOVEit Transfer (May–June 2023): One File-Transfer Zero-Day, Thousands of Victims

By OnCloudSec Research Team · Published Oct 6, 2026 · 6 min read

Facts in this article were checked against the sources listed below as of Oct 5, 2026.

Retrospective: this article looks back at events from June 2023, written in 2026 with the benefit of hindsight.

Beginning on May 27, 2023, the CL0P ransomware gang — also tracked as TA505 — started exploiting a previously unknown SQL injection vulnerability in MOVEit Transfer, Progress Software's managed file transfer product. CISA and the FBI described the campaign in a joint advisory on June 7, 2023. Within weeks, MOVEit had become one of the largest data breach events on record, touching thousands of organizations and tens of millions of people through their employers, insurers, pension funds, universities and government agencies.

How it unfolded
  1. Zero-day SQL injectionCL0P exploits CVE-2023-34362 in internet-facing MOVEit Transfer web applications from May 27, 2023.
  2. Web shell installedA web shell named LEMURLOOT, disguised as human2.aspx, gives the attackers command execution.
  3. Database theftThe web shell is used to pull files and records out of the underlying MOVEit databases.
  4. Extortion, not encryptionVictims are named on CL0P's leak site and pressured to pay to keep stolen data private.
  5. Supply-chain cascadeOrganizations whose payroll, benefits or service providers used MOVEit learn they were exposed too.

What made MOVEit unusual wasn't only its scale. CL0P didn't bother encrypting systems. It stole data and threatened to publish it. And many victims weren't MOVEit customers at all — they were customers of vendors who used it.

What happened

MOVEit Transfer is designed to exchange files securely with partners, which means it usually sits on the internet and holds exactly the files organizations most want to protect: payroll exports, benefits enrollment, claims data, customer records and financial reports.

According to the CISA and FBI advisory, the attackers used the SQL injection flaw (CVE-2023-34362) to install a web shell called LEMURLOOT on internet-facing MOVEit Transfer web applications. The file was named human2.aspx to blend in with the legitimate human.aspx file. Through the web shell, the attackers could run commands on the server and extract data from the underlying MOVEit databases.

Progress released patches and mitigations quickly, and further vulnerabilities in the product were found and fixed in the following weeks. But mass exploitation had already happened in a short window, reportedly around a US holiday weekend — a timing pattern ransomware groups use deliberately.

How the attack worked

The attack chain was short, which is part of why it was so effective:

  1. Find internet-facing MOVEit Transfer servers (trivial with internet scanning).
  2. Exploit the SQL injection flaw to gain the ability to plant a file.
  3. Use the web shell to enumerate and download data.
  4. Leave, and start the extortion campaign later.

There was no phishing, no stolen password, no lateral movement through Active Directory. The entire operation targeted one application that, by design, held concentrated sensitive data and faced the internet.

CL0P had used the same playbook before against other file transfer products — Accellion FTA in 2020–2021 and Fortra GoAnywhere earlier in 2023. In hindsight, the group's interest in managed file transfer was a strong signal that defenders could have acted on.

Why it mattered

Data theft without encryption is still a crisis. Many organizations had invested in backups and ransomware recovery. Those investments did nothing here. The damage was disclosure: regulatory notifications, lawsuits, credit monitoring and reputational harm.

The blast radius ran through vendors. A large share of affected organizations learned of their exposure from a payroll provider, a benefits administrator or another service partner. They had never heard of MOVEit, let alone patched it. Third-party and fourth-party risk became concrete.

Retention made it worse. File transfer platforms often keep files for months or years because nobody configured deletion. Every stale file was data the attackers could take.

What to do now

If you run any managed file transfer, SFTP or integration platform — on-premises, in Azure or in AWS — treat it as a crown-jewel system.

  1. Inventory internet-facing data exchange services. Use external attack surface scanning (for example Microsoft Defender External Attack Surface Management) and your cloud inventories to list every file transfer, SFTP and integration endpoint. Assign an owner to each.
  2. Shorten retention aggressively. Files should be deleted from transfer platforms within days of successful delivery. Data that isn't there can't be stolen.
  3. Restrict who can reach the service. Where partners connect from known networks, allowlist their IP ranges. Put admin interfaces behind identity-aware access with MFA, never directly on the internet.
  4. Put it on the emergency patch list. File transfer products should be patched within days of a critical advisory, especially when a vulnerability appears in CISA's Known Exploited Vulnerabilities catalog.
  5. Front web interfaces with a WAF (Azure Front Door or Application Gateway WAF, AWS WAF) and log requests to your SIEM.
  6. Monitor for web shells and bulk exports. Alert on new .aspx or script files in application directories, web server processes spawning shells, and outbound data volumes above baseline.
  7. Ask your vendors. In third-party reviews, ask which file transfer tools your payroll, benefits and other data processors use, how long they keep your files, and how quickly they patch.

How to detect this kind of attack

Mass exploitation of file transfer products tends to leave three kinds of evidence:

  • New files in web directories. LEMURLOOT was a single ASPX file. On Windows hosts with Microsoft Defender for Endpoint, query DeviceFileEvents for .aspx files created under the application's web root, and alert on anything not deployed by your release process.
  • Web server processes doing unusual things. IIS worker processes (w3wp.exe) spawning cmd.exe or powershell.exe, or making outbound connections to unfamiliar hosts, deserve immediate review.
  • Data leaving in bulk. Compare outbound volumes from the server against its normal baseline using NSG flow logs in Azure or VPC Flow Logs in AWS. A file transfer server suddenly sending gigabytes to a new destination is a strong signal.

CISA's advisory included indicators of compromise and detection signatures. When a vendor or CISA publishes indicators, search your logs for them going back to the earliest known exploitation date — not just from the day you patched.

Common mistakes

  • Patching without hunting. Applying the fix closes the door, but it doesn't remove a web shell already installed. Many organizations patched quickly and only later discovered data had been taken days earlier.
  • Treating the vendor's SaaS as someone else's problem. Even when a provider hosts the platform, you decide what data goes into it and how long it stays.
  • Forgetting the admin interface. Management consoles for file transfer platforms are often reachable from the internet with only a password.
  • Not knowing who your vendors' vendors are. The first many organizations heard of MOVEit was a breach notification from a payroll or benefits provider.

Questions for leadership

  • Which systems exchange our sensitive data with partners, and are any internet-facing?
  • How long do files stay on those systems after delivery?
  • Which of our vendors hold our employees' or customers' data, and how do they move it?
  • If a vendor told us tomorrow that our data was stolen through their tool, do we know our notification obligations and timelines?

Key takeaways

  • Managed file transfer platforms concentrate sensitive data and face the internet by design.
  • CL0P showed that data extortion alone can be devastating — backups don't help.
  • Short retention, restricted access and emergency patching are the most effective defenses.
  • Your exposure includes the tools your vendors use, not just your own.

Sources

  1. CISA and FBI: #StopRansomware — CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability (AA23-158A)
  2. Tenable: FAQ for MOVEit Transfer vulnerabilities and CL0P
moveit breachMOVEit2023

More on this story