
DNS Security 101: Protect Against DNS Hijacking
August 2, 2026In May 2023, a single SQL injection flaw in Progress Software’s MOVEit Transfer application exposed the sensitive data of more than 2,700 organizations and an estimated 95 million individuals worldwide — making it one of the most consequential supply chain breaches in recorded history. What made this incident uniquely instructive wasn’t the sophistication of the attack vector itself. It was a well-understood vulnerability class, exploited by a ransomware-adjacent group called Cl0p. What made it catastrophic was the cascading failure of third-party risk management across entire industries simultaneously. Three years later, as organizations reflect on the lessons still unlearned, the MOVEit breach remains the defining case study for how dependency on managed file transfer and SaaS vendors creates systemic exposure that perimeter defenses simply cannot address.
Understanding the Attack Surface MOVEit Exposed
MOVEit Transfer is not exotic software. It’s an enterprise-grade managed file transfer (MFT) tool used extensively in healthcare, financial services, government, and logistics — precisely the sectors that handle the most sensitive regulated data. Progress Software’s product was trusted because it was purpose-built for compliance-heavy environments: HIPAA, SOX, PCI-DSS workflows all ran through it. That trust, ironically, is what made it so dangerous as a single point of failure.
The vulnerability itself — tracked as CVE-2023-34362 — was a critical SQL injection flaw in MOVEit’s web-facing interface. Exploiting it required no authentication. An unauthenticated attacker could manipulate database queries to escalate privileges and deploy a custom web shell named LEMURLOOT. From there, Cl0p exfiltrated data at scale before victims even detected the intrusion. The average dwell time before detection in file transfer breaches in 2023 was 197 days, according to IBM’s Cost of a Data Breach Report — but Cl0p moved faster, compressing exfiltration into hours rather than months.
Why Managed File Transfer Tools Are High-Value Targets
MFT platforms sit at a uniquely dangerous intersection: they are internet-facing, they aggregate data from multiple internal systems for outbound transfer, and they are often exempt from the same scrutiny applied to primary business applications. Security teams frequently treat them as infrastructure rather than applications — meaning they receive patch cycles measured in weeks rather than hours, and logging configurations are often minimal. For Cl0p, targeting MOVEit wasn’t arbitrary; it was a deliberate strategy of identifying a widely-deployed tool where a single zero-day would yield thousands of victims simultaneously.
The Third-Party Risk Management Failures That Amplified the Damage
The breach’s true scale wasn’t determined by Progress Software’s failure alone — it was multiplied by the collective failure of organizations to understand and govern their vendor relationships adequately. A 2024 study by the Ponemon Institute found that 61% of organizations experienced a data breach caused by a third party in the preceding 12 months, yet only 34% maintained a comprehensive inventory of all third-party vendors with access to sensitive data. MOVEit was, for many victims, precisely that kind of undocumented dependency.
Consider the downstream cascades: The Louisiana Office of Motor Vehicles lost data on 6 million residents not because Louisiana was a direct MOVEit customer, but because a state contractor was. Shell, Siemens Energy, Sony, and the BBC all found themselves compromised through similar contractual chains. The attack demonstrated that an organization’s security posture is only as strong as its nth-party risk — not just its direct vendors.
The Inventory Problem: You Cannot Protect What You Cannot See
Most enterprise vendor inventories are catastrophically incomplete. Security teams maintain lists of major SaaS platforms and cloud providers, but the long tail of specialized tools — file transfer utilities, data integration middleware, legacy EDI platforms — often escapes formal registration in vendor risk programs. MOVEit was running in many organizations without appearing in any security risk register. When the breach was announced, incident responders in affected companies faced a fundamental question they couldn’t immediately answer: Do we use MOVEit? Does any vendor we share data with use MOVEit? The inability to answer that question within minutes, not days, is a governance failure with quantifiable consequences.
Lessons for Vendor Due Diligence and Continuous Monitoring
Traditional third-party risk management operates on a questionnaire-and-annual-review model that the MOVEit breach conclusively demonstrated is structurally inadequate. A vendor completing a SOC 2 Type II audit in January poses a fundamentally different risk profile in June after an unpatched vulnerability surfaces in one of their dependencies. Static assessments capture a point-in-time snapshot of controls; they provide no visibility into the dynamic threat landscape around a vendor’s actual technology stack.
The post-MOVEit standard demands continuous monitoring across three distinct dimensions:
- Attack surface intelligence: Continuous external scanning of vendor-facing infrastructure for exposed services, certificate anomalies, and newly published CVEs affecting known vendor technologies.
- Dark web and threat intelligence feeds: Monitoring for early indicators that a vendor’s credentials or data are circulating in threat actor communities before formal breach disclosure.
- Contractual SLA enforcement: Binding vendors to specific patch application timelines for critical CVEs, with audit rights and defined notification windows when vulnerabilities in their stack are published.
Operationalizing a Fourth-Party Risk Framework
The Louisiana OMV scenario — breached through a contractor’s contractor — demands that organizations extend their risk programs beyond direct vendor relationships. A fourth-party risk framework requires vendors to disclose their own material subprocessors and critical technology dependencies. This isn’t hypothetical governance theater; it’s a contractual and regulatory imperative. Under GDPR Article 28, data processors are already required to obtain controller approval before engaging sub-processors. The challenge is operationalizing this requirement into actionable intelligence rather than contract language that sits in a drawer.
Leading organizations now require vendors to maintain a Software Bill of Materials (SBOM) for all software deployed in environments that process client data. When CVE-2023-34362 was published, an organization with vendor SBOMs could have queried within minutes whether MOVEit Transfer appeared in any vendor’s disclosed software inventory. Without SBOMs, that determination required weeks of emails and phone calls — weeks in which data was already gone.
Incident Response Failures and Coordination Gaps
When Cl0p made its mass extortion demands public on June 6, 2023, many victim organizations were still unaware they had been breached. The notification gap between breach occurrence and victim awareness averaged 12 to 21 days across the incident’s first wave. This delay wasn’t primarily attributable to Cl0p’s stealth; it was a product of inadequate log retention, insufficient SIEM alerting on MFT activity, and the absence of formal vendor breach notification agreements.
Progress Software issued its initial alert on May 31, 2023 — but the voluntary, reactive nature of that disclosure meant organizations had to self-identify whether they were affected. CISA subsequently issued emergency directives for federal agencies, but the private sector had no equivalent coordination mechanism at scale. The incident exposed a critical gap: there is no established playbook for coordinating incident response across thousands of simultaneous third-party breach victims.
Building Notification Chains Before They’re Needed
The organizations that responded most effectively to MOVEit had two things in common: they had pre-established relationships with threat intelligence sharing communities (ISACs relevant to their sector), and they had contractual provisions requiring vendors to notify them of suspected incidents within 72 hours — the same standard the GDPR imposes on data controllers toward supervisory authorities. Waiting for a vendor’s PR-cleared breach notification letter is not a viable incident response strategy. By the time that letter arrives, forensic evidence may have aged beyond usefulness and regulatory reporting windows may already be closing.
Regulatory and Legal Consequences That Reshaped Compliance Expectations
The MOVEit breach generated regulatory consequences that extended well beyond Progress Software. The U.S. Department of Health and Human Services issued guidance clarifying that HIPAA-covered entities remained liable for breaches at their business associates regardless of how the breach originated. The FTC opened investigations into multiple affected organizations’ third-party risk practices, not their own security controls. In the EU, supervisory authorities in multiple member states launched inquiries under GDPR Article 83 — with potential fines based not on the initial breach, but on the adequacy of the victim organization’s vendor oversight program.
This regulatory posture reflects a fundamental shift: regulators now treat third-party risk management as a primary control domain, not a supporting process. The SEC’s cybersecurity disclosure rules, finalized in late 2023, reinforced this by requiring public companies to disclose material third-party incidents and describe the adequacy of their vendor risk programs. The question is no longer whether a vendor was breached — it’s whether your organization had reasonable controls to detect, limit, and respond to that breach.
How Contractual Provisions Now Define Security Posture
Legal teams at leading enterprises are now treating vendor contracts as security instruments. Provisions that were previously aspirational — right-to-audit clauses, mandatory penetration testing disclosure, specific patch timelines for critical CVEs — are becoming non-negotiable baseline requirements. Post-MOVEit model vendor agreements in financial services and healthcare now routinely include: indemnification for data breach costs attributable to vendor negligence, mandatory participation in the client’s incident response exercises, and specific requirements around vulnerability disclosure within 24 hours of CVSS score publication for any software in scope.
Key Takeaways
- Vendor inventory completeness is a security control, not an administrative task. If your organization cannot identify within minutes whether a newly disclosed CVE affects a vendor in your supply chain, your risk program has a material gap. Invest in automated vendor technology discovery and Software Bill of Materials programs immediately.
- Static annual assessments are insufficient for dynamic threat environments. Continuous monitoring of vendor attack surfaces, combined with threat intelligence feeds tracking vendor-specific compromise indicators, must replace or substantially supplement questionnaire-based due diligence cycles.
- Fourth-party risk is not optional in regulated industries. The Louisiana OMV scenario — and dozens like it from the MOVEit incident — demonstrate that sub-processor risk must be contractually governed, inventoried, and monitored. Require vendors to disclose material subprocessors and enforce SBOM requirements for all in-scope software environments.
- Incident response coordination must be pre-established, not improvised. Contractual 72-hour breach notification requirements, pre-registered participation in relevant ISACs, and tabletop exercises that include third-party breach scenarios should be standard components of every enterprise security program.
- Regulators will evaluate your vendor oversight program, not just the breach itself. The SEC, FTC, and EU supervisory authorities have all signaled that third-party risk governance is a primary compliance domain. Document your vendor risk methodology, maintain evidence of continuous monitoring activities, and treat vendor contracts as security instruments with legally enforceable control requirements.
Conclusion: From Reactive to Structural
The MOVEit breach was not an anomaly. It was a preview. The combination of widely-deployed enterprise software, internet-exposed management interfaces, and fragmented third-party risk programs will continue to produce mass-casualty breach events until organizations treat supply chain security as a structural discipline rather than a compliance checkbox. The tools and frameworks exist — continuous threat exposure management, SBOM integration, fourth-party risk programs, contractual security SLAs — but deployment has lagged behind the threat landscape by years.
Three years after MOVEit, the organizations that have translated its lessons into operational controls are meaningfully better positioned. Those that filed it away as a case study without changing governance structures remain as exposed to the next Cl0p campaign as they were in May 2023.
Start this week with a concrete action: Commission an audit of your current vendor inventory against your data flow diagrams. Identify every third party — and every known subprocessor — that touches sensitive data. For each one, confirm that your contract includes a 72-hour breach notification requirement and a right-to-audit provision. That gap analysis alone will surface the structural vulnerabilities that the next MOVEit-scale campaign is already designed to exploit.
💡 Enjoyed this article?
Subscribe for more expert insights delivered to your inbox.
Follow us or subscribe below xe2x80x94 free, no spam.





