The cyber gang has been linked to the MOVEit Transfer zero-day vulnerability exploit, according to a statement by Microsoft Threat Intelligence on Monday. Among the firms understood to be affected, Zellis – a UK payroll and HR software provider – is confirmed to be among them.
Once the MOVEit vulnerability attack was noticed, Zellis said it immediately disconnected the server, and notified the Information Commissioner’s Office, Deposit Protection Corporation, and the National Cyber Security Centre.
However, the company confirmed to Sky News that eight of its clients were implicated. While Zellis did not disclose which clients were impacted, British Airways, the BBC, and Boots have all confirmed they were affected.
BA warned, in an email seen by the Telegraph, that the compromise could include names, addresses, national insurance numbers, banking details and more. Boots has disclosed that the staff names, surnames, employee numbers, dates of birth, email addresses, home addresses, and national insurance numbers have been breached for a “very small number” of employees.
The BBC told Sky News that employee banking details were not exposed, however company ID and national insurance numbers may have been compromised. “We are aware of a data breach at our third party supplier, Zellis, and are working closely with them as they urgently investigate the extent of the breach,” said the BBC.
“The issue appears to be an SQL injection vulnerability within the MOVEit software, which enables unauthorised remote attackers to exploit the system and subsequently, gain access to sensitive information via the database,” said Javvad Malik, lead security awareness advocate at KnowBe4.
The attacks are believed to have taken place on 27 May during the US Memorial Day, holidays being a popular time of attack for large scale exploitation attacks when staff are at a minimum.
Recommended
- DfT Awards £1.96M to Innovative Transport Tech Projects
- Supply Chain Productivity Decline Cannot be Solved by Tech Alone
- Unleashing Rural Productivity: New Gov Doc Focuses on Broadband
According to Bleeping Computer, the ransomware gang behind the attack has not yet begun extorting the victims. At this point it is believed the gang is reviewing the data to determine how it could be leveraged to make demands from the breached companies.
In a recent attack on Forta’s GoAnywhere software by Clop in February, the gang waited over a month to email ransom demands to the organisations.
“In the end, proactive cybersecurity measures can help guard against cyberattacks, but organisations must also prepare for scenarios where a system vulnerability is exploited and no patch is available yet, such as is the case with zero-day vulnerabilities,” said Malik. “This breach serves as a dire reminder that organisations need to remain vigilant and work constantly to identify and mitigate these risks to protect their data and their stakeholders.”





