SEC investigating MOVEit hack that exposed data of at least 64 million people

Progress Software disclosed that it has received a subpoena from the SEC to share information relating to the vulnerability in its file transfer software, MOVEit, which became the subject of a massive exploit beginning last May. According to the filing, the investigation is presently a "fact-finding inquiry," and there's no indication at this time that Progress has "violated federal securities laws." The company intends to cooperate with the SEC.

One report by cybersecurity software company Emsisoft estimates that the MOVEit breach exposed the information of at least 64 million individuals through 2,547 affiliated organizations. Among the organizations impacted by the zero-day vulnerability are the Louisiana Office of Motor Vehicles and the Colorado Department of Health Care Policy and Financing. Sony confirmed its employee data was compromised in the exploit earlier this month. And Michigan-based financial services provider, Flagstar Bank, sent its customers a notice that said records had been stolen (they'll now receive free identity monitoring services for two years.)

The culprits of the attack — the CL0P ransomware gang — "helped pioneer the practice of double-extortion," according to Reuters. In this sort of scheme, the ransomers both encrypt the target's data and threaten to leak said data (unless they're paid.) The group have since made clearweb sites to leak some of the data they've exfiltrated in the MOVEit hack, from companies like Kirkland and TD Ameritrade. The FBI have since offered up to $10 million to anyone with information that could link CL0P to any particular foreign government.

The true cost (both to victims and Progress Software) remain unknown at this time. But some of the affected customers have begun seeking restitution for the breach. Progress disclosed in the same regulatory filing that it is a party to 58 class action lawsuits at this time. Many of those may be consolidated as they progress, but they still present the possibility of enormous civil penalties.

This article originally appeared on Engadget at https://www.engadget.com/sec-investigating-moveit-hack-that-exposed-data-of-at-least-64-million-people-163057853.html?src=rss https://www.engadget.com/sec-investigating-moveit-hack-that-exposed-data-of-at-least-64-million-people-163057853.html?src=rss
Created 1y | Oct 12, 2023, 4:40:16 PM


Login to add comment

Other posts in this group

Elon Musk says a 'massive cyberattack' is to blame for X being down

Perhaps like the loser of the proposed cage fight between Elon Musk and Mark Zuckerberg

Mar 10, 2025, 8:50:17 PM | Engadget
PlayStation's Mark Cerny says a version of FSR 4 could be implemented on the PS5 Pro

AMD just debuted its new FidelityFX Super Resolution 4 (FSR 4) upscaling tech on the latest

Mar 10, 2025, 8:50:15 PM | Engadget
Volunteer photographers are fixing Wikipedia's terrible celebrity headshots

Go to a profile of any celebrity on Wik

Mar 10, 2025, 8:50:14 PM | Engadget
Apple is reportedly planning a major redesign for iOS 19 and macOS 16

Apple is planning to dramatically rethink the look and feel of its operating systems with the introduction of the next version of iOS, iPadOS and macOS,

Mar 10, 2025, 8:50:13 PM | Engadget
Apple's AirPods Pro 2 are down to $170 at Amazon

Now's a good time to pick up a pair of

Mar 10, 2025, 6:30:24 PM | Engadget
The Last of Us season two promises a lot more action alongside devastating drama

Season two of HBO’s The Last of Us is just a month away, and as such the hype cycle kicked into full gear this past weekend. A full trailer finally arrived on Saturday during a panel at SX

Mar 10, 2025, 6:30:23 PM | Engadget