One of the largest breaches of 2023 didn’t begin with a stolen password — it began with software. The Cl0p ransomware group exploited a zero-day vulnerability in Progress Software’s widely used MOVEit Transfer tool, then worked methodically through everyone who relied on it. By the time the dust settled, the breach had touched well over 1,000 organisations and tens of millions of individuals worldwide, from banks and universities to government agencies.
What made MOVEit so damaging was the cascade: organisations that had never even heard of the tool were exposed because a supplier, or a supplier’s supplier, used it.
Why this matters
- Your security includes your suppliers — you can do everything right internally and still be exposed through third-party software.
- Zero-days are inevitable — what counts is how fast you detect, patch and respond when one appears.
- Know where your data lives — you can’t protect what you can’t see, especially data held by vendors.
- Breach response is a capability — having a plan ready turns a crisis into a process.
What we’d advise
We help clients keep software patched promptly, map where their sensitive data actually sits (including with suppliers), and ask hard questions of their vendors. If you’re not sure who has access to your data, that’s exactly where to start.
Source: widely reported in 2023, including by Reuters and BleepingComputer; attributed to the Cl0p/Clop ransomware group.
