Supply chain
β Supply Chain
PBI Research Services (PBI) Third-Party Breach (June 2023)
Primary Source βIncident Details
MOVEIt breach impacts Genworth, CalPERS as data for 3.2 million exposed. PBI Research Services (PBI) has suffered a data breach with three clients disclosing that the data for 4.75 million people was stolen in the recent MOVEit Transfer data-theft attacks. These attacks started on May 27th , 2023, when the Clop ransomware gang began exploiting a MOVEit Transfer zero-day vulnerability to allegedly steal data from hundreds of companies. Over the past week, the Clop gang began extorting companies by slowly listing impacted organizations on its data leak site as they attempt to pressure victims to pay a ransom demand. Third-party company: Ipswitch, Inc..
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Ipswitch, Inc.
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2023-06-01 Breach occurred
- 2023-06-23 Publicly disclosed