In late May 2023, the Clop ransomware group (also written Cl0p) began exploiting a zero-day SQL injection vulnerability in MOVEit Transfer, an enterprise managed file transfer (MFT) application widely used for secure file sharing in regulated industries. The vulnerability, CVE-2023-34362, allowed unauthenticated attackers to execute SQL injection and ultimately run arbitrary commands on MOVEit Transfer servers. Clop used automated exploitation tools to hit every internet-exposed MOVEit instance they could find, exfiltrating data from each.
The scale of what followed was extraordinary. By the time CISA and Progress Software (MOVEit's vendor) published advisories on June 1, 2023, Clop had already compromised hundreds of organizations. Over the following months, the total grew to over 2,700 confirmed victim organizations - making MOVEit the largest mass exploitation campaign by victim count in history at that point. The victims spanned every sector: US federal agencies (including the Department of Energy), state governments, universities, banks, healthcare systems, pension funds, airlines, and hundreds of others in dozens of countries. The common thread was MOVEit Transfer.
How Clop Executed the Campaign
Clop's MOVEit operation had been in preparation for months. Mandiant later determined that Clop had been testing the MOVEit vulnerability as early as July 2021 - nearly two years before exploitation began. The group used that time to understand the vulnerability, develop reliable exploitation tooling, and prepare for a mass campaign. When they activated in late May 2023, the scale and automation were impressive: hundreds of organizations were compromised within days.
The exploitation pattern was relatively simple: Clop used SQL injection in MOVEit's web interface to interact with the backend database, enumerate user accounts, and ultimately deploy a web shell (named "LEMURLOOT") that provided persistent access. From this web shell, automated tooling exfiltrated data stored on the MOVEit server - typically the files that organizations had uploaded to MOVEit for secure transfer, plus the configuration database containing MOVEit user accounts and their associated data.
Clop's model for the MOVEit campaign differed from traditional ransomware. Rather than deploying encryption (which would have immediately alerted victims and triggered incident response), Clop focused exclusively on data theft and extortion. They did not encrypt victim systems. Instead, they exfiltrated data and then approached victims with demands - pay or the stolen data would be published on Clop's data leak site. This "data-only extortion" approach allowed Clop to operate at far greater scale than encryption-based ransomware, since exfiltration was significantly faster and less operationally complex than deploying a ransomware binary across enterprise networks.
The Victims and Scale
The breadth of MOVEit victims illustrated how a single vulnerability in a widely used file transfer product could cascade into thousands of organizations. MOVEit Transfer was particularly common in regulated industries - healthcare, financial services, government - where secure file transfer compliance requirements drove adoption. These were exactly the organizations with data valuable for extortion.
Among the high-profile US victims: the Oregon and Louisiana DMVs (combined 9 million driver's license records), the New York City school system (45,000 students' data), Maximus (a US government contractor serving Medicare and Medicaid programs, 11 million beneficiaries' records), Shell, Siemens Energy, PricewaterhouseCoopers, EY, Aon, the BBC, British Airways, and Boots the UK pharmacy chain. The UK victims shared a common thread: all used Zellis, a UK payroll provider that used MOVEit. A single compromise of Zellis's MOVEit instance cascaded to all of Zellis's clients.
The US Department of Energy confirmed it was among those compromised. The DOE data was exfiltrated from two DOE entities that used MOVEit. CISA offered technical assistance to all affected federal agencies. The scale of US government exposure in a single third-party software vulnerability was notable and reinforced debates about FISMA requirements for software supply chain security.
Clop's Track Record and the Supply Chain Amplification
Clop's MOVEit operation was not the first time the group had exploited a file transfer zero-day for mass theft. In early 2023, Clop had exploited a zero-day in Fortra's GoAnywhere MFT (CVE-2023-0669), hitting approximately 130 organizations. Before that, the group had used a zero-day in Accellion's legacy File Transfer Appliance in late 2020, hitting around 100 organizations. The pattern was clear: Clop had developed a specialization in finding and exploiting file transfer software zero-days for mass data theft operations.
The supply chain amplification effect - where a single compromise of a service provider (like Zellis) cascades to all that provider's clients - was the most operationally interesting aspect of the campaign. Clop didn't need to individually target BBC, British Airways, and Boots; it only needed to compromise Zellis. The downstream victims had no ability to control Zellis's MOVEit security posture; they were exposed by their service provider's choice and security practices. This asymmetry - where victims' security was determined by a supplier they didn't control - drove subsequent regulatory focus on third-party risk management and supply chain security requirements.