According to US security researchers. The software’s manufacturer, Progress Software, had recently disclosed a security vulnerability that could potentially allow unauthorized access to users’ systems.
MOVEit Transfer, created by Progress Software, is a managed file transfer software that facilitates the exchange of files and data between organizations, including business partners and customers. The exact number of affected organizations and the extent of the breaches are currently unknown.
Progress Software’s Chief Information Officer, Ian Pitt, confirmed that fixes had been made available for the vulnerability since its discovery on May 28. He stated that the cloud-based service associated with the software had also been impacted, but no exploitation had been observed thus far.
Cybersecurity firms Rapid7 and Mandiant Consulting (owned by Google) reported multiple instances where the security flaw had been exploited to steal data. Charles Carmakal, Chief Technology Officer of Mandiant Consulting, noted that mass exploitation and broad data theft had occurred in recent days. In the past, similar zero-day vulnerabilities in managed file transfer solutions have led to data theft, leaks, extortion, and victim-shaming.
Both Rapid7 and Mandiant advised organizations to prepare for potential extortion and public release of the stolen data, although the motivation of the threat actor remains unknown. Rapid7 observed an increase in compromise cases related to the disclosed flaw.
Progress Software has provided guidelines for users at risk to mitigate the impact of the security vulnerability. Pitt refrained from commenting on the identity of the data thieves and stated that there was no evidence of malware distribution.
Pitt mentioned that MOVEit Transfer had a smaller customer base compared to Progress Software’s other software products, which exceed 20 in number. The company is collaborating with forensics partners to gain a comprehensive understanding of the situation and its evolving nature.


