Supply chain
⛓ Supply Chain
DHL Third-Party Breach (June 2023)
Primary Source ↗Incident Details
Extreme Networks emerges as victim of Clop MOVEit attack | Computer Weekly. Network equipment and services supplier Extreme Networks has revealed its instance of Progress Software’s MOVEit tool was compromised in the ongoing Clop cyber attack. Extreme Networks has disclosed that it is the latest technology company affected by the fast-developing MOVEit cyber attack , with downstream customers of the network hardware and services supplier potentially at risk of having had their data stolen by the Clop (aka Cl0p) cyber extortion operation. In a message published on Wednesday 7 June , Extreme Networks CISO Philip Swain said: “We recently learned that our instance of the Progress Software MOVEit Transfer tool was impacted by a malicious act. We took immediate action, employing our security protocols, and have contained impacted areas. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2023-06-01 Breach occurred
- 2023-06-09 Publicly disclosed