HHS told Congress a MOVEit breach at contractors affected more than 100,000 people

Organization
U.S. Department of Health and Human Services (HHS)
Exploit
Third-Party Data Breach
Industry
Federal Government

The U.S. Department of Health and Human Services told Congress in late June 2023 that data on more than 100,000 people had been exposed through the MOVEit file transfer campaign. Under the Federal Information Security Modernization Act, an incident touching 100,000 or more individuals is classed as a major incident and has to be reported to lawmakers.

HHS said the compromised data was held by third-party vendors rather than by the department itself. An agency official said attackers reached the information by exploiting a vulnerability in the MOVEit Transfer software those vendors used, and that no HHS systems or networks were compromised. The department did not name the contractors involved.

The underlying flaw, tracked as CVE-2023-34362, was a SQL injection vulnerability in Progress Software's MOVEit Transfer product. Progress identified and patched it on May 31, 2023, after the Cl0p ransomware group had already begun mass exploitation. Cl0p claimed responsibility for the wider campaign and threatened to extort the organizations it had hit.

HHS was one of several federal bodies caught up in the campaign, either directly or through suppliers. The Department of Energy also confirmed exposure, and hundreds of organizations worldwide were affected, among them Johns Hopkins University, British Airways and the BBC. As of early July 2023, HHS had not published a count of individual notifications and said its review under federal security rules was continuing.

Sources