Criminals have exploited a vulnerability in Progress Software’s MOVEit file transfer app, which is used by thousands of organisations around the world.
A number of organisations whose supply chains use the MOVEit app have suffered a data breach as a result, with customer and/or employee data being stolen.
Organisations around the world have been affected by this incident, some of which have confirmed that personal data may have been stolen.
What can I do?
If you work for an affected organisation, and you are concerned about your personal information, follow our guidance below for individuals affected by a data breach.
If you are an organisation directly affected by this vulnerability, see our guidance for organisations.
For organisations directly affected, Progress (the vendor of the MOVEit software) has issued updated advice on mitigating this vulnerability, which includes a new patch for additional vulnerabilities that could be exploited. MOVEit customers should apply the latest vulnerabilities fixes, as described in the MOVEit Transfer Knowledge Base Article(Updated 15th June).
Cyber attacks like this that target organisations' supply chains (rather than the organisation directly) are increasingly common. In addition to our well-established Supply chain principles, we have recently provided: