UNPATCHED THIRD-PARTY SOFTWARE
A previously unknown SQL injection vulnerability in the MOVEit file transfer tool was mass-exploited by the Cl0p ransomware group before a patch was available. UK payroll provider Zellis used MOVEit to exchange files with its clients, so when its instance was compromised, the personal data of employees at British Airways, the BBC, Boots, and Aer Lingus was exposed, including national insurance numbers, dates of birth, and home addresses. None of these employers used MOVEit directly, and none had a contract with it — the exposure came entirely through a supplier’s supplier. Every affected organisation reported the breach to the ICO. Globally, the vulnerability affected over 2,700 organisations and around 93 million people.
Source: The Register, July 2023