British Airways, BBC, Boots affected by MOVEit vulnerability

Share post:

British Airways, the BBC, and U.K. pharmacy chain Boots fell victim to a data breach caused by a vulnerability in the MOVEit document-transfer application. Microsoft’s Lace Tempest team has confirmed that the breach was orchestrated by individuals associated with the Russian Clop ransomware gang.

The intrusion took advantage of a flaw in Zellis’ infrastructure. Zellis reported that their MOVEit installation was infiltrated, leading in unlawful access and theft of information from a small number of its clients, including British Airways, the BBC, and Boots. Zellis, on the other hand, promised its clients that the compromise had no impact on its own software.

The security researchers discovered that the cybercriminals exploited a vulnerability in MOVEit, a software used by Zellis, for at least a month before detection. The developer, Progress, has released a patch to fix the vulnerability (CVE-2023-34362).

The exact number of people affected, and the degree of exposed data are unknown, but the firm are said to be assisting the impacted employees. Both British Airways and Zellis disclosed the breach to the UK Information Commissioner’s Office (ICO) in reaction to the breach. Zellis also contacted the Irish privacy watchdog and the British cyber-police.

The sources for this piece include an article in TheRegister.

SUBSCRIBE NOW

Related articles

Microsoft reveals critical security flaw affecting Android apps

Microsoft has identified a serious vulnerability in Android apps that could allow malicious software to hijack legitimate apps...

Chinese government websites “Riddled with security flaws” say researchers

A recent study conducted by researchers from the Harbin Institute of Technology reveals significant security issues plaguing Chinese...

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways