Hackers Exploit Security Flaw in Popular File Transfer Tool MOVEit to Steal User Data

It was not immediately clear which or how many organizations use the software or were impacted by potential breaches.

Advertisement
By Reuters | Updated: 3 June 2023 11:40 IST
Highlights
  • Progress Software had made fixes available
  • It discovered the vulnerability late on May 28
  • The software's eponymous cloud-based service had also been impacted

Software maker Progress Software disclosed the vulnerability on Wednesday

Hackers have stolen data from the systems of a number of users of the popular file transfer tool MOVEit Transfer, US security researchers said on Thursday, one day after the maker of the software disclosed that a security flaw had been discovered.

Software maker Progress Software Corp, after disclosing the vulnerability on Wednesday, said it could lead to potential unauthorized access into users' systems.

Advertisement

The managed file transfer software made by the Burlington, Massachusetts-based company allows organizations to transfer files and data between business partners and customers.

It was not immediately clear which or how many organizations use the software or were impacted by potential breaches. Chief Information Officer Ian Pitt declined to share those details but said Progress Software had made fixes available since it discovered the vulnerability late on May 28.

Advertisement

The software's eponymous cloud-based service had also been impacted by this, he told Reuters.

"As of now we see no exploit of the cloud platform," he said.

Advertisement

Cybersecurity firm Rapid7 and Mandiant Consulting - owned by Alphabet's Google - said they had found a number of cases in which the flaw had been exploited to steal data.

"Mass exploitation and broad data theft have occurred over the past few days," Charles Carmakal, chief technology officer of Mandiant Consulting, said in a statement.

Advertisement

Such "zero-day," or previously unknown, vulnerabilities in managed file transfer solutions have led to data theft, leaks, extortion, and victim-shaming in the past, Mandiant said.

"Although Mandiant does not yet know the motivation of the threat actor, organizations should prepare for potential extortion and publication of the stolen data," Carmakal said.

Rapid7 said it had noticed an uptick in cases of compromise linked to the flaw since it was disclosed.

Progress Software has outlined steps users at risk can take to mitigate the impact of the security vulnerability.

Pitt did not have a comment on who might have been trying to steal data by exploiting the flaw.

"We have no evidence of it being used to spread malware," he said.

MOVEit Transfer was used by a relatively "small" number of customers compared to those of the company's other software products that number more than 20, he said.

"We have forensics partners on board and we are working with them to make sure that we have an ever-evolving grasp of the situation." 

© Thomson Reuters 2023 


Apple's annual developer conference is just around the corner. From the company's first mixed reality headset to new software updates, we discuss all the things we're looking forward to seeing at WWDC 2023 on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Hackers, MOVEit Transfer
Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Nord 6 India Launch Date, Colour Options, Key Features Revealed
  2. Vivo X300 Ultra Camera Details Revealed as Handset Surfaces on Geekbench
  3. Samsung Galaxy A37, Galaxy A57 Price Details Emerge Ahead of March 25 Launch
  4. Oura Ring 5 Design, Colours Options Leaked Ahead of Expected Launch in 2027
  5. Redmi Note 15 SE 5G Confirmed to Launch in India on This Date
  6. Leaked Honor 600 Series Images Suggest it Will Strongly Resemble This iPhone
  7. Apple Announces WWDC 2026 for June 8: What to Expect
  8. Redmi Note 16 Series Might Launch With This Key Upgrade Over Note 15 Lineup
  9. Vivo X300s Leak Hints at Key Specifications Ahead of Launch Next Week
  10. Vivo T5x 5G Goes on Sale in India for the First Time: Price, Sale Offers
  1. Redmi Note 15 SE 5G India Launch Date Announced as Company Reveals Key Features
  2. DarkSword iOS Toolkit Now Public on GitHub, Lowering Barrier for Potential iPhone Exploit
  3. Bitcoin Trades Near $70,000 as Geopolitical Developments Support Crypto Markets
  4. Vivo T5x 5G Goes on Sale in India for the First Time: Price, Specifications, Sale Offers
  5. iQOO Z11 Chipset, Display and Other Key Features Revealed a Day Before Its Launch in China
  6. OnePlus Nord 6 India Launch Date, Amazon Availability Confirmed; Colour Options, Key Features Revealed
  7. Oura Ring 5 Design, Colours Options Leaked Ahead of Anticipated Launch in 2027
  8. Redmi Note 16 Series Tipped to Launch With Upgraded Battery, Similar Camera Hardware as Predecessor
  9. Honor 600 Pro, Honor 600 Leaked Renders Point to iPhone 17 Pro-Like Design; Tipped to Get 9,000mAh Battery
  10. Oppo Find X9 Ultra Tipped to Launch in China, Global Markets on April 20; India Debut Expected Later
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.