Supply chain β›“ Supply Chain

Hatch Bank GoAnywhere MFT Breach (Cl0p, CVE-2023-0669)

πŸ“… 2023-01-30 🏒 Fortra GoAnywhere Managed File Transfer (MFT) 🦠 Cl0p πŸ”Ž CVE-2023-0669
Primary Source β†—

Incident Details

Hatch Bank, a fintech-focused bank-as-a-service provider headquartered in San Francisco, was an early confirmed victim of the Cl0p ransomware group’s mass exploitation of CVE-2023-0669 in Fortra’s GoAnywhere MFT platform.

Fortra notified Hatch Bank of the security incident on February 3, 2023. Unauthorized access to files stored on Fortra’s GoAnywhere service occurred between January 30 and January 31, 2023 β€” the same two-day window as the Community Health Systems breach and others in Cl0p’s ~130-victim GoAnywhere campaign.

Approximately 139,493 customers had their names and Social Security numbers stolen. The breach notification filed with the Maine Attorney General noted 630 Maine residents among the affected population. Because the stolen data was limited to names and SSNs (no financial account numbers or payment card data), the incident is classified as a PII/identity theft risk rather than a direct financial fraud event, though the combination is sufficient for identity theft.

Hatch Bank offered 12 months of complimentary credit monitoring services to affected individuals. The bank filed breach notifications with relevant state attorneys general and notified customers in early March 2023.

CVE-2023-0669 is a pre-authentication command injection flaw in GoAnywhere MFT’s administrative console scored CVSS 7.2. Fortra quietly issued a private advisory on January 30, 2023, and released patch version 7.1.2 on February 7. Security researchers at Censys and others identified hundreds of internet-exposed GoAnywhere instances during the campaign window.

The GoAnywhere exploitation campaign by Cl0p β€” stealing data from over 130 organizations in roughly ten days without deploying file-encrypting ransomware β€” was a pivotal demonstration of the group’s shift to pure data extortion via MFT platform zero-days. The same playbook was applied at much larger scale against MOVEit Transfer in May 2023.

Technical Details

Initial Attack Vector
Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra's GoAnywhere MFT administrative interface, to access Hatch Bank's file transfer environment on January 30–31, 2023 and steal customer names and Social Security numbers
Vendor / Product
Fortra GoAnywhere Managed File Transfer (MFT)
Malware Family
Cl0p
CVE / GHSA References
CVE-2023-0669
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2023-01-30 Breach occurred
  2. 2023-03-02 Publicly disclosed
  3. 2023-03-02 Customers notified