Supply chain
β Supply Chain
Dublin Airport Third-Party Breach (June 2023)
Primary Source βIncident Details
Dublin Airport staff pay data hit by criminals. Attackers accessed it via third-party services provider, says management group. It’s an awkward Monday for Dublin Airport after pay and benefits details for some 2,000 staff were apparently “compromised” following a recent attack on professional service provider Aon. Aon appears to be the latest victim of the massive supply chain attack sweeping the world via a since-patched flaw β CVE-2023-34362 β in Progress Software’s massively popular MOVEit file transfer suite. Progress first disclosed the flaw on May 31, and issued a patch the the next day . The vendor has since patched another two critical flaws . If you’re a MOVEit transfer customer, you need to check for updates ASAP using the vendor’s KB article here. Third-party company: Aon.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Aon
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-06-01 Breach occurred
- 2023-07-03 Publicly disclosed