MOVEit zero-day at payroll provider Zellis exposed staff data at BA, BBC and Boots
- Organization
- Zellis
- Exploit
- Supply Chain Attack
- Industry
- Payroll Services
Zellis, a payroll and human resources provider that says it serves about a third of the FTSE 100 and processes more than 60 million payslips a year, was compromised through a zero-day vulnerability in the MOVEit Transfer software it used to exchange files with customers.
The flaw, tracked as CVE-2023-34362, was an SQL injection vulnerability in Progress Software's MOVEit Transfer that allowed unauthenticated attackers to reach the underlying database. It was disclosed at the end of May 2023 and was already being exploited at scale, with roughly 2,500 internet facing MOVEit instances identified by May 31. Microsoft attributed the campaign to the actor it tracks as Lace Tempest, which runs the Clop extortion operation.
Zellis said a small number of its customers had been affected by the global issue. Employees of British Airways, the BBC, Boots and Aer Lingus were among those notified in the first week of June 2023, and Tech Monitor reported that at least eight Zellis customers were hit. British Airways told staff that names, addresses, National Insurance numbers and banking details for its UK and Ireland payroll had been taken. Boots said the exposed fields included names, employee numbers, dates of birth, email addresses, National Insurance numbers and the first line of home addresses.
Zellis disconnected the affected server, engaged external incident response specialists and notified the Information Commissioner's Office, Ireland's Data Protection Commission and the National Cyber Security Centre.