What Was MOVEit? The Breach That Reached People Who Never Used It
The file was called human2.aspx. It sat in the same directory as human.aspx, which is a real page that ships with MOVEit Transfer and has done for years.
An administrator scrolling a directory listing reads that as one file and a copy of it. Somebody chose the name for exactly that reason, and for a few weeks it worked.
Everyone remembers MOVEit as a very large breach, and the number gets quoted on its own. The number is not the interesting part. Who it reached is: the overwhelming majority of the people whose data was taken had never heard of MOVEit, did not use it, and had never made a decision about it in their lives.
What was MOVEit?
MOVEit Transfer is a managed file transfer product from Progress Software. It is the software an organisation installs when it needs to move large, sensitive files between itself and other organisations on a schedule, with an audit trail. Payroll files. Pension records. Benefits enrolments. Student transcripts.
CVE-2023-34362 was a SQL injection vulnerability in its web application, reachable without authentication, that could be escalated to remote code execution. Progress disclosed it on 31 May 2023.
By then it had been in use for days.
The bug, and the weekend
Exploitation began around 27 May 2023 — the Saturday of the US Memorial Day weekend, chosen for the same reason every mass exploitation event is timed to a holiday. The people who would notice were not at their desks, and would not be for three days.
That is not opportunism. Kroll's investigators later found evidence that the group had been probing MOVEit's exploitability as far back as July 2021, and had built and tested the tooling well in advance. The weekend was the trigger date, not the discovery date.
Two more MOVEit vulnerabilities followed within weeks — CVE-2023-35036 on 9 June and CVE-2023-35708 on 15 June — which is the usual pattern once a product gets looked at properly for the first time by people who are motivated.
human2.aspx
The webshell dropped on compromised servers was named human2.aspx, placed in the wwwroot directory beside MOVEit's genuine human.aspx.
It accepted commands through a request header and could enumerate the Azure Blob Storage or on-disk file store behind the appliance, retrieve files, create an administrative session, and add or delete users. It was written to blend into the application, not to be clever.
The naming is worth dwelling on because it is the whole tradecraft in one detail. The attacker did not hide the file. They put it in the most obvious directory on the box, and gave it a name that a tired administrator's eye slides over.
Cl0p had done this twice already
MOVEit is usually reported as if it appeared from nowhere. It was the third one.
- Accellion FTA, December 2020 into 2021 — a twenty-year-old file transfer appliance, exploited through a chain of zero-days, roughly a hundred organisations affected including universities, law firms and state agencies.
-
Fortra GoAnywhere MFT, February 2023 —
CVE-2023-0669, around 130 organisations, including Community Health Systems and the City of Toronto. - Progress MOVEit Transfer, May 2023.
Three managed file transfer products, three years running, same group. The category was selected deliberately, and the reason is structural: a file transfer appliance is the one box in an organisation that is supposed to hold a concentrated copy of everything sensitive, is supposed to be reachable from the internet, and is usually owned by whichever team needed it rather than by security.
It is the highest ratio of records to hosts available anywhere in a normal enterprise.
Why the victim count is so strange
Around 2,700 organisations appear in the tallies. That is not a large number of MOVEit installations — it is roughly what you would expect for a mid-market enterprise product.
The people count is where it goes strange, and the reason is who ran it.
Zellis, a payroll provider, ran MOVEit. Zellis did payroll for the BBC, British Airways, Boots and Aer Lingus. One appliance, four household names, and not one of those four had ever evaluated MOVEit, contracted for it, or been told it existed.
The same shape repeats down the list. The National Student Clearinghouse reported exposure affecting around 900 member institutions. Maximus, a US government services contractor, reported roughly 11 million individuals. Welltok, a healthcare communications firm, around 8.5 million. Two US state motor vehicle agencies lost large portions of their licence-holder records. The US Department of Energy was reached through two separate entities.
Not one of those is an organisation whose customers chose MOVEit. They are organisations whose suppliers did, or whose suppliers' suppliers did.
What the 90 million actually counts
The figures quoted are usually "more than 2,700 organisations" and "over 90 million individuals." They come from Emsisoft's running tally, which was maintained openly and updated for well over a year as disclosures trickled out. The final counts settled a little higher than that.
Two honest caveats belong with the number.
First, it counts individuals notified, not distinct people. One person can appear several times — through an employer, a former employer, a health plan and a state agency — and there is no way to deduplicate across thousands of independent notifications. The real number of distinct humans is lower, and unknowable.
Second, it is a floor, not a ceiling. It only includes organisations that disclosed. The tally grew for eighteen months precisely because disclosure arrived in waves, and the last wave is never provably the last.
What the number does establish is the shape: a single vulnerability in a single mid-market product produced a breach measured in tens of millions of people, because of where that product sits.
No encryption at all
Cl0p is filed as a ransomware group and MOVEit is filed under ransomware. Nothing in the MOVEit campaign was encrypted.
They took files and left. The extortion came afterwards, by naming victims on a leak site on a schedule, over months, with a stated deadline of 14 June 2023 for organisations to make contact. They also posted a note claiming government data would be deleted unasked — a claim with no way to verify it and no reason to believe it.
The economics are the reason. Encrypting 2,700 organisations means 2,700 negotiations, 2,700 decryptors, and 2,700 incident response teams working against you at once. Taking the files means the same leverage with none of the operational load, and it sidesteps every backup strategy the victims spent a decade building.
The industry spent years telling organisations that good backups defeat ransomware. Good backups do nothing whatsoever about this.
What is still true
Progress patched, and patched again, and MOVEit is not meaningfully more dangerous today than any comparable product. That was never the exposure.
The durable finding is that an organisation's breach surface includes every vendor its vendors use, that this list is not knowable from the inside, and that no patch cycle, asset inventory or vulnerability scan run inside your own estate touches any of it. The BBC could have run a flawless security programme in 2023 and the outcome would have been identical.
Third-party risk questionnaires existed before MOVEit and were not the answer, because the question they ask stops at the first tier.
Further reading
- Progress Software — MOVEit Transfer critical vulnerability advisory, 31 May 2023, and the subsequent June advisories.
- Mandiant — Zero-Day Exploitation of MOVEit Transfer (UNC4857), June 2023.
- Kroll — MOVEit Transfer: Cl0p activity dating to 2021, June 2023. The evidence for advance testing.
- Emsisoft — the public MOVEit victim tally, maintained through 2023 and 2024.
- CISA and FBI — Joint Advisory AA23-158A, #StopRansomware: Cl0p Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability, 7 June 2023.
EXHIBIT 0017 — MOVEIT
We put it on a shirt. A steel filing drawer pulled all the way open, drawn as an engraving, packed front to back with identical hanging folders. Two tabs stand up taller than the rest: human.aspx and, right beside it, human2.aspx. A thread runs out of the second one, over the lip of the drawer, and off the bottom of the design.
The callouts are the incident: ONE OF THESE IS NOT THEIRS, SQL INJECTION, MEMORIAL DAY WEEKEND, MOST VICTIMS NEVER RAN IT. Most people see a filing drawer. Anyone who has ever read a directory listing at two in the morning sees the second tab.
That's the whole idea.