Ofcom said MOVEit hack took data on 412 staff and companies it regulates
- Organization
- Ofcom
- Exploit
- Hacking
- Industry
- Government Regulator
Ofcom, the United Kingdom's communications regulator, said on June 12, 2023 that it had been caught in the mass exploitation of MOVEit Transfer, the managed file transfer product made by Progress Software.
The regulator said attackers downloaded "a limited amount of information about certain companies we regulate", some of it confidential, together with personal data belonging to 412 Ofcom employees. Reporting at the time said the staff records included addresses and bank details.
Ofcom said it acted immediately to prevent further use of the MOVEit service and to apply the recommended security measures. It alerted the regulated companies whose information was involved and said it was continuing to support affected staff.
The Clop group claimed responsibility for the wider campaign, which exploited a zero-day flaw in MOVEit and swept up hundreds of organizations. The gang had set a June 14 deadline for victims to make contact before it began naming them on its extortion site. Researchers counted more than 2,000 MOVEit servers exposed to the internet at the time, 128 of them in the UK.
Ofcom was one of several British organizations affected. A separate compromise at payroll provider Zellis had already exposed data at the BBC, British Airways, Boots and Aer Lingus.