BA, BBC, Boots Are The Newest Victims of Clop Ransomware’s MOVEit Exploit

Yesterday, British Airways, Boots and BBC were among many who have had personally identifiable data stolen. That includes names, contact details, salaries, and national insurance numbers of tens of thousands employees. This was due to a breach of Zellis which is a payroll provider, and their use of the MOVEit file transfer software. In a separate statement, the Nova Scotia government also reported being hit.  


On Sunday, Microsoft said this:

In short, Microsoft believed the group behind the hacks was “Lace Tempest”,  a sub group to online extortionists who run the Clop ransomware site. 

In a statement yesterday, MOVEit said it had fixed the SQL injection vulnerability and was working with experts to further investigate the issue. 

Meanwhile, threat intelligence analyst Germán Fernández said this:

 In short, he had discovered at least 57 other instances of potential MOVEit compromises, with the list of organizations including U.S. governments and banking organizations, such as the FBI and JP Morgan Chase. 

Roy Akerman, Co-Founder & CEO, Rezonate:

   “The MOVEit Transfer SQL injection vulnerability allows un-authenticated attacker to gain access to its Transfer’s database. From there it can recon data, structure, as well as running modification and deletion commands.

“Security teams are advised to go back at least 90 days and investigate any potentially malicious attempts as initial scanning observed by GreyNoise started March 3rd. In addition, rotating relevant keys and credentials are important to make sure no further access, if compromised, is available.“

Clearly if you use MOVEit, you should be making sure that you take the mitigation steps outlined here so that you don’t become the next victim of Clop.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading