Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On July 17, 2023, SecurityWeek reported that more than 340 organizations and 18 million individuals had reportedly been affected by the MOVEit hack. That was a dated tally—not a final, audited count. The attack exploited a flaw in internet-facing MOVEit Transfer systems to steal files, and exposure could reach customers or employees whose data was held by an affected organization.

How many organizations were affected by the MOVEit hack?

SecurityWeek reported on July 17, 2023, that the number of reportedly impacted organizations had passed 340 and the number of individuals had exceeded 18 million. The figures describe what had been reported by that date; they should not be treated as a definitive global census or a current total. Government sources confirm the attack method and document specific downstream incidents, but do not provide one consolidated final count.

The word “impacted” can cover different groups: an organization whose MOVEit Transfer server was compromised, or a customer, employee, or partner whose information was held by a compromised organization. A count may also depend on which victims have been identified or reported. The July 17 report is the source for the 340-plus figure; it does not establish a single counting method that resolves every downstream relationship.

What happened in the MOVEit breach?

MOVEit Transfer is Progress Software’s managed file-transfer application, used by organizations to exchange files. According to the joint FBI and CISA advisory, CL0P, also known as TA505, began exploiting CVE-2023-34362 on May 27, 2023. The vulnerability was a previously unknown SQL injection flaw in MOVEit Transfer. Attackers used it to install the LEMURLOOT web shell on internet-facing systems and retrieve files from the underlying system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

The campaign focused on data theft and extortion. Mandiant reported early exploitation and theft; on June 6, 2023, it reported that CL0P had claimed the campaign and threatened to disclose stolen data if victims did not pay. That does not mean every affected organization experienced file encryption or received identical demands: the documented mechanism was access and theft, followed by threatened disclosure.

Why were customers and employees affected?

An organization can hold files on behalf of other organizations or people. When attackers accessed an exposed MOVEit system, those files could include customer or employee information, even if those people did not use MOVEit themselves. The UK National Cyber Security Centre noted that organizations whose supply chains used the application suffered breaches involving customer and/or employee data. This is a third-party software incident with downstream victims; it does not mean the vendor’s own corporate network was compromised in every case.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

The sequence illustrates how one vulnerable service can create multiple layers of exposure: the software instance is compromised, files stored there are accessed, and the organizations or individuals represented in those files may then require notification. Which layer is counted as an “impacted organization” can vary by report.

What data was at risk?

The exposed information depended on the files each organization stored in MOVEit. There was no single data set shared by all victims. CMS’s notices about Maximus Federal Services, a government contractor, show how the consequences varied: CMS said files in the contractor’s MOVEit application may have included Medicare beneficiary information. CMS estimated approximately 612,000 current Medicare beneficiaries were impacted in its earlier notice, then identified an additional 330,000 current beneficiaries potentially impacted in a later notice. These are Maximus-related figures from separate CMS notices, not components that should automatically be added to the global tally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

In the Maximus case, CMS said its own systems were not compromised. It reported that Maximus detected unusual activity on May 30, 2023, stopped using its MOVEit application early May 31, and believed unauthorized activity copied files stored in the application during approximately May 27–31. These dates describe that incident, not every victim’s timeline.

How the incident unfolded

Date What was reported
May 27, 2023 FBI/CISA and Mandiant identified this as the start of exploitation of CVE-2023-34362.
May 30–31, 2023 In the Maximus incident, unusual activity was detected May 30 and use of the application stopped early May 31, according to CMS.
May 31, 2023 Progress announced the vulnerability and issued guidance, as recounted in CMS’s notice.
June 6, 2023 Mandiant reported CL0P’s claim of responsibility and threat to disclose stolen data.
June 7, 2023 FBI and CISA published a joint advisory with technical details and mitigation guidance.
July 17, 2023 SecurityWeek reported more than 340 organizations and 18 million individuals reportedly impacted.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should an organization do if it used MOVEit Transfer?

Organizations that operated an internet-facing MOVEit Transfer instance during the exploitation period should assess their own exposure rather than assume that patching alone resolves the incident. Follow the FBI/CISA advisory and Progress’s current vulnerability fixes and mitigation guidance. The UK NCSC also directs compromised organizations to updated Progress guidance. Because vendor and government instructions can change, use their current official versions during response.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
  • Determine whether the organization ran an affected, internet-facing MOVEit Transfer version and whether it was exposed during the exploitation window.
  • Review the advisory’s technical indicators and available logs for signs of access or compromise; preserve evidence as part of incident response.
  • Establish what files were stored on the instance and identify the customers, employees, or partners whose information may be involved.
  • Use current vendor and government guidance for mitigation and remediation, and assess notification obligations for affected people and organizations.

What should I do if I received a MOVEit breach notice?

Start with the notice from the employer, service provider, contractor, or agency that contacted you. It should identify the data involved in that organization’s incident and explain any assistance or actions specific to your case. A MOVEit notice does not by itself mean every category of personal information—or every account you have—was exposed.

CMS’s Maximus notices described complimentary 24-month credit monitoring, information about free credit reports, and a replacement Medicare card with a new number for beneficiaries whose Medicare Beneficiary Identifier might have been affected. Those measures apply to that response; they are not benefits offered universally to everyone affected by the MOVEit campaign. Follow the instructions in your own notice and relevant government guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.