Metaluxo
← Blog

The MOVEit Breach: Supply Chain Attacks Are the New Normal

The MOVEit Breach: Supply Chain Attacks Are the New Normal

In May 2023, a zero-day vulnerability in MOVEit Transfer — a widely used managed file transfer software — was exploited by the Clop ransomware group. The breach affected over 600 organisations and an estimated 40 million individuals. The BBC, British Airways, Boots, and the University of Rochester were among the victims.

The MOVEit breach is a textbook example of a supply-chain attack: the attacker did not target the end organisations directly. They targeted a vendor that those organisations trusted, and used that trust as a foothold.


How the attack worked

MOVEit Transfer is a web application that organisations use to send and receive large files. The vulnerability (CVE-2023-34362) was a SQL injection flaw that allowed unauthenticated remote code execution.

The Clop group discovered the vulnerability, developed an exploit, and used it to install a webshell on MOVEit servers. From there, they exfiltrated data and extorted victims.

The attack was not sophisticated in execution — SQL injection is one of the oldest vulnerabilities in web security. What made it devastating was the breadth of the attack surface: one vulnerability, hundreds of victims.


Why supply-chain attacks are growing

Supply-chain attacks are attractive to attackers because they are efficient. Instead of breaching 100 companies individually, an attacker breaches one vendor and gains access to 100 companies’ data.

The trend is accelerating:

  • SolarWinds (2020): Compromised build pipeline, 18,000 customers affected
  • Kaseya (2021): Ransomware via MSP tools, 1,500 businesses affected
  • Log4j (2021): Vulnerability in ubiquitous logging library, millions of systems affected
  • MOVEit (2023): File transfer vulnerability, 600+ organisations affected

For SMEs, the risk is not that you will be targeted directly. It is that you use the same tools as everyone else, and those tools are the targets.


What SMEs can do

Know your supply chain. Maintain a register of every vendor that processes your data or has access to your systems. Include the software they use, especially if it is internet-facing.

Monitor vendor security advisories. Subscribe to security bulletins for your critical vendors. When a vulnerability is announced, you have hours, not days, to assess your exposure.

Reduce internet-facing footprint. If you do not need a file transfer server on the public internet, put it behind a VPN. Every exposed service is a potential entry point.

Have an incident response plan that includes vendors. When a vendor breach happens, you need to know: what data did they have, who do you notify, and how do you recover?


At Metaluxo we run supply-chain risk assessments for SMEs. If you are unsure which of your vendors pose the greatest risk, book a free 30-minute consultation and we will identify your critical dependencies.

Roberto Arias — founder of Metaluxo. Virtual CISO work, ISO 27001 and incident response for small and medium businesses across the EU. Ask him a question →

Send us a message
Message us Book now