MOVEit’s Ledger: 2,700 Orgs, 93 Million People
Cl0p's June 2023 listing waves turned the MOVEit breach into a running census — 2,700+ organizations and ~93M individuals per Emsisoft tallies. The economics of encryption-free extortion.
Cl0p's June 2023 listing waves turned the MOVEit breach into a running census — 2,700+ organizations and ~93M individuals per Emsisoft tallies. The economics of encryption-free extortion.
CVE-2023-2868 gave pre-auth RCE in Barracuda's email gateways via spreadsheet parsing, exploited since October 2022. The final verdict: replace every appliance. Remediation doctrine lessons.
CVE-2023-34362 in MOVEit Transfer let Cl0p deploy the LEMURLOOT web shell at scale over Memorial Day weekend — pure data extortion, no encryption, hundreds of downstream victims.
Ireland's DPC fined Meta €1.2B over EU-US transfers that Schrems II had already doomed — the largest GDPR fine ever, ordering suspension and deletion. Transfer-governance lessons for security teams.
A server-side fault in ASUS's firmware-update mechanism crashed routers worldwide, requiring manual recovery — a global outage delivered through the trusted update path, no attacker required.
A 2023 PoC scraped the KeePass master password from memory via a rogue DLL; the maintainer called it working as designed. Both were right — and the endpoint-is-the-perimeter lesson stuck.
Operation Cookie Monster seized the market selling browser sessions, cookies, and saved credentials for ~2M identities, with 119 arrests across 17+ countries. Session-security lessons.
MSI's ransomware extorted Intel BootGuard OEM signing keys onto underground markets — keys that certify firmware as bootable. Key ceremony lessons.
CVE-2023-27350 gave unauthenticated RCE on PaperCut MF/NG servers across schools and hospitals, with access handed toward ransomware crews.
WD's 2023 intrusion took My Cloud services offline mid-extortion claims, locking users out of their own files. Cloud-tethered storage lessons.
3CX's signed desktop app shipped a trojan after its build pipeline fell to an upstream vendor compromise — the first documented double supply-chain attack.
SVB's March 2023 run froze payroll for half of venture-backed tech and minted a fraud wave targeting displaced customers. Treasury continuity lessons.