MOVEit’s Ledger: 2,700 Orgs, 93 Million People

📋 Key Takeaways
  • What happened
  • Anatomy of the cascade
  • Timeline
  • Defensive lessons
  • Why it still matters in 2026
5 min read · 822 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

Quick Answer — By mid-June 2023, the MOVEit breach stopped being “a vulnerability” and became a ledger: Cl0p’s leak-site name-and-shame listings pushed the running total toward what would settle at 2,700+ organizations and roughly 93 million individuals (per Emsisoft’s rolling tallies) — the largest pure data-extortion event yet recorded. No encryption, no downtime theater: just stolen archives and countdown clocks. The lesson for the decade: extortion without encryption scales better than ransomware ever did — and the victims list grows downward, through supply chains, for years.

What happened

  • The escalation cadence: Beginning June 2, Cl0p posted batches of victims weekly — hundreds of organizations at a time — with a standing “we’re just getting started” tone. Each posting was itself an attack: customers, regulators, and journalists did the notification math in public.
  • The tallies (hedged): Emsisoft’s trackers, the de-facto census, counted 2,700+ affected organizations and ~93M individuals by the count’s maturity, including waves of downstream victims — schools, pension systems, government agencies — who never ran MOVEit themselves.
  • The economics: Cl0p skipped costly encryption, helpdesk extortion, and restoration drama. Pure theft compresses the kill chain: fewer interactions, less infrastructure, no decryptors to maintain, and payouts negotiated quietly against publication threats.

Anatomy of the cascade

Ring Who they were Exposure
Direct Appliance operators (payroll processors, service bureaus) Own data + full customer archives
Second wave Operators’ customers (employers, agencies) Employee/beneficiary data via vendors
Third wave Downstream of those (unions, insurers, dependents) Data they never knew transited MOVEit
Long tail Individuals and class-action umbrellas Notification, credit monitoring, litigation
data-hmmnm-seam="2">

Timeline

Date Event
2023-05-27 Mass exploitation of CVE-2023-34362 begins (see our May entry)
2023-06-02 First Cl0p victim listings; the extortion clock starts
2023-06-14 (our peg) Listing waves accelerate; org counts pass the hundreds, headlines shift from “bug” to “breach census”
2023-06 → 12 Cascades surface (MAXIMUS, state agencies, universities; downstream tallies climb)
2024 → 2025 Class actions consolidate; regulatory filings; tallies freeze near 2,700 orgs / ~93M individuals per Emsisoft
data-hmmnm-seam="3">

Defensive lessons

  • Count your data relationships, not just your vendors. Third-wave victims had no contract with any MOVEit operator — their exposure existed inside someone else’s file transfer. Mapping inbound data flows is now table stakes.
  • Extortion response ≠ ransomware response. No systems to restore means the crisis is disclosure strategy, regulatory sequencing, and comms — disciplines most IR plans mention in one paragraph and practice never.
  • Track the census-keepers. Emsisoft-style tallies and regulator dashboards became the authoritative narrative; being countable (accurate, timely notification) beats being counted (estimated, late).
  • Assume publication regardless. Cl0p’s credibility incentive — proving leaks are real — makes “maybe they’ll delete it” fantasy. Plan for the archive’s eventual release, not its disappearance.
  • Legal exposure scales with rows, not systems. One popped appliance produced ninety-million-row liability; data minimization is litigation-risk management, not hygiene.
data-hmmnm-seam="4">

Why it still matters in 2026

MOVEit’s escalation month established the metrics of mass extortion — headcounts of orgs and individuals as the public’s measure of a breach — and every headline campaign since has been graded on that ruler. Cl0p’s pure-theft model became the template: subsequent zero-day sprees (whatever the MFT/vendor target of the season) followed the same list-extort-count playbook, and insurers repriced accordingly. The 2026 defense contract is the one MOVEit wrote: fewer archives, mapped data flows, rehearsed disclosure, and boards that understand extortion’s unit economics. The 93 million learned it by mail.

data-hmmnm-seam="5">

The MAXIMUS cascade, in miniature

One June listing illustrated the whole geometry: MAXIMUS — a government-services contractor running MOVEit for state and federal programs — disclosed that the breach reached 8–11 million individuals whose data transited its services (per its filings; counts evolved). None of them were MAXIMUS’s “users” in any product sense; they were beneficiaries of public programs — the third ring of the cascade, counted in millions from a single operator’s archive. Regulators reviewing that disclosure drafted the questions that became 2024’s vendor-notification requirements: who holds our beneficiaries’ data, through what chains, and who tells whom when a chain breaks? The MOVEit ledger answered by example: everyone, eventually, and late — unless the mapping was done before the clock started.

Why did Cl0p skip encryption?

Because encryption is a cost center for extortionists: it requires operator engagement, victim-facing support, and decryption infrastructure — all fragile and all evidence. Pure theft needs one competent bug and patience. The shift also blunted defenders’ favorite narrative (“we restored quickly”) — when nothing goes down, uptime press releases celebrate an empty room.

Were the 2,700+ orgs all direct MOVEit customers?

Far from it — direct victims numbered in the hundreds; the rest inherited the breach through payroll processors, benefits administrators, and government contractors whose appliances held their data. That inversion (most victims had no MOVEit relationship) is the supply-chain lesson regulators spent 2024 turning into vendor-notification duties.

What happened to the stolen data?

Consistent with Cl0p’s stated policy: non-payers got published in stages; payers’ archives presumably stayed sold-or-shelved. Researchers documented… hedge: reporting on post-breach misuse (.identity fraud waves traceable to specific MOVEit victims) remained partial, in part because notification letters deliberately under-specify what left. Assume circulation; design accordingly.

Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.