The MOVEit mass exploitation of 2023 was a SQL injection zero-day (CVE-2023-34362) in Progress Software's MOVEit Transfer managed file transfer product, exploited at scale by the Cl0p ransomware group (also tracked as TA505) to steal data from a reported 2,700-plus organisations and more than 90 million individuals worldwide, according to breach trackers Emsisoft and KonBriefing, before patches closed the flaw. It matters to Indian firms not because of the exact victim count — which varied by tracker — but because it is the clearest recent proof that a single vulnerability in one shared vendor product can compromise thousands of downstream organisations simultaneously, regardless of each victim's own security posture. This is the supply-chain and third-party risk problem in its purest form, and it is exactly the exposure most Indian mid-market firms have not mapped.
What Actually Happened With MOVEit
MOVEit Transfer is a managed file transfer (MFT) platform used by enterprises, government agencies, payroll processors, and healthcare organisations to move sensitive files — payroll data, health records, financial statements — between systems and partners. In late May 2023, Progress Software disclosed a critical SQL injection vulnerability, tracked as CVE-2023-34362, that allowed unauthenticated attackers to gain access to the underlying database and, from there, execute code and exfiltrate files stored on the platform.
The Cl0p ransomware group, a financially motivated cybercrime operation with a long history of exploiting file-transfer software, had reportedly been testing and exploiting the flaw before the public disclosure — a classic zero-day pattern where exploitation precedes patching. Once Progress Software released fixes and the vulnerability became public, security researchers and trackers began cataloguing victim organisations as Cl0p published names on its extortion leak site, a technique the group has used consistently: exfiltrate data quietly, then use public naming and shaming as leverage instead of (or alongside) encrypting systems.
Why This Was a Supply-Chain Attack, Not Just a Software Bug
The distinction matters for how Indian firms should respond. A traditional vulnerability disclosure affects organisations that run the software directly. MOVEit's impact spread further because MFT platforms sit at trust boundaries — they exist specifically to receive and hold sensitive files from and for other organisations. When Cl0p compromised a payroll processor's MOVEit instance, it didn't just steal that processor's data; it stole data belonging to every client whose payroll files passed through that instance. Victim disclosures following the campaign repeatedly showed this second-order pattern: an organisation had never installed MOVEit itself, but a vendor, partner, or service provider it relied on had, and that relationship became the breach path.
The campaign's reported scale also illustrates how quickly disclosures compounded once the leak site process began. Trackers following the MOVEit campaign, including security researchers and breach-notification services, updated victim counts over several months as more affected organisations came forward or were named — a slow-burn disclosure pattern that is now typical of large-scale MFT and file-transfer exploitation campaigns, seen previously in incidents involving Accellion FTA and GoAnywhere MFT.
Why Indian Firms Should Care Even Without Direct India-Specific Figures
Precise India-specific victim or record counts from the MOVEit campaign were not consistently or reliably reported in public trackers, and this article does not invent figures that were not published. What is directly relevant to Indian firms is the structural exposure the campaign revealed, and that structure is identical here.
Indian enterprises — BPOs, IT services firms, payroll and HR outsourcers, banks, insurers, and healthcare providers — routinely move sensitive files through third-party managed file transfer tools, vendor portals, and outsourced processing partners. Many of these relationships are invisible to the client organisation's own security team because the file transfer happens entirely on the vendor's infrastructure. A vulnerability in that vendor's platform becomes the client's breach, even though the client never installed or patched the vulnerable software itself.
Under India's Digital Personal Data Protection (DPDP) Act, 2023, a Data Fiduciary remains accountable for personal data it has entrusted to a Data Processor, including third-party file transfer and outsourcing vendors. A vendor's zero-day exposure does not shift that accountability — it is the Data Fiduciary's obligation to have reasonable security safeguards in place and to notify affected individuals and the Data Protection Board in the event of a personal data breach, regardless of whose software failed.
The Third-Party Risk Gap Most Firms Have
Most Indian mid-market organisations run a vendor risk questionnaire once at onboarding and rarely revisit it. That approach misses exactly the failure mode MOVEit demonstrated: a vendor can pass every questionnaire and still run a product with an undiscovered zero-day. The controls that would have reduced blast radius are operational, not contractual.
| Control | What It Would Have Limited in a MOVEit-Style Event |
|---|---|
| Internet-facing exposure inventory | Identifies which vendor-hosted file transfer endpoints are reachable from the public internet at all |
| Patch SLA in vendor contracts | Forces a defined window for emergency patching, reducing days of unpatched exposure |
| Data minimisation with processors | Limits what personal or financial data ever transits a third-party MFT tool in the first place |
| Segmented, time-limited access | Prevents a compromised transfer server from becoming a pivot point into wider vendor or client networks |
| Continuous vendor attack-surface monitoring | Surfaces newly disclosed CVEs against vendor-run software before an attacker exploits them at scale |
| Breach notification clauses | Ensures the Data Fiduciary learns of a processor compromise fast enough to meet DPDP notification duties |
Know your vulnerabilities before attackers do
Run a free VAPT scan — takes 5 minutes, no signup required.
Book Your Free ScanPatch Velocity: The Difference Between a Bug and a Breach
Progress Software released patches for CVE-2023-34362 quickly after disclosure, and later related MOVEit vulnerabilities followed the same rapid-patch pattern. The organisations that avoided becoming Cl0p's next named victim were overwhelmingly the ones that applied emergency patches within hours or days, not weeks. This is the operational lesson that translates directly to any Indian firm running internet-facing software of any kind: the time between "patch available" and "patch applied" is the exposure window, and for an actively exploited zero-day that window is being measured by attackers, not by IT's normal change-management calendar.
Vendor Risk Management: What Changes After MOVEit
The campaign is a strong argument for treating vendor and processor risk as a continuous discipline rather than a point-in-time checklist. A practical shift for Indian firms includes maintaining a live inventory of which vendors and processors handle personal or sensitive data, requiring vendors to disclose their own patching cadence and incident history, and running independent vulnerability assessment and penetration testing — including on vendor-facing integration points where feasible — rather than relying solely on vendor self-attestation. Where regulatory or high-assurance testing is required, that work should be delivered with a CERT-In empanelled partner to satisfy formal audit and compliance requirements.
Running a free VAPT scan on your own internet-facing assets is a starting point, but the MOVEit campaign shows that visibility has to extend to the vendors and processors handling your data too — not just your own infrastructure. Bachao.AI, built by Dhisattva AI Pvt Ltd, offers an automated VAPT platform that helps Indian SMBs and mid-market firms build that continuous visibility instead of a once-a-year audit. For guidance on the breach-notification and processor-accountability duties this kind of incident triggers, see the DPDP compliance guide, and browse the Bachao.AI blog for more incident breakdowns like this one.