MOVEit & Zellis data security attack puts thousands of employees at risk

ramsac cybercovid 1 e1585644078953

In case you missed it, last week the news headlines once again featured a serious data breach, with the revelation that the personal information of thousands of employees’ personal data had been breached in planned attack on the data of Zellis, an outsourced payroll company.

In brief, Zellis are a payroll company that provide an outsourced service to some pretty large organisations, including the BBC, British Airways and Boots. They use a piece of software called MOVEit, for transferring files between themselves and their clients.

It has been reported that Cybercriminals are exploiting a zero-day vulnerability in MOVEit, to perform a mass download of data. Data stolen includes staff ID numbers, dates of birth, home addresses, national insurance numbers and banks details.

A zero-day vulnerability is a flaw in a system or application that there is no defense against because the system or application maker is unaware it exists.

Zellis have confirmed that data was stolen from 8 of its client firms. The BBC have informed employees that their personal data was stolen, while staff of British Airways were informed their bank details may have been stolen. Many other organisations have been impacted by this attack and the numbers are expected to rise. It is not confirmed who is behind this attack, but there is speculation that notorious Cl0p ransomware group, thought to be based in Russia, may be behind it according to Microsoft.

An updated version of the MOVEit software has been released and the National Cyber Security Centre has urged organisations using this software to carry out security updates as soon as possible. However, an internet scan revealed that thousands of company databases are still vulnerable because they haven’t been updated according to reports.

Attacks like these are a reminder that all of us need to have strong security resilience in place. It is essential that you

  1. Have an understanding of your supply chain. Your company data doesn’t just reside in your own system, you likely share data via your supply chain, be that professional advisors, outsourced service providers, or even your IT suppliers. Our recent blog gives more information on how to audit your supply chain
  2. Ensure that someone in your business is receiving daily alerts about zero day threats and is ascertaining if you need to take immediate action. Our secure+ service provides this service on your behalf.
  3. Have a plan for emergency patching when new vulnerabilities are released
  4. Have a plan for ongoing patching and software updates which should happen across all platforms at least once a month
  5. It is important that organisations have Cyber Incident Response Plans (CIRP) in place that outlines procedures and guidelines for responding to any potential cyber incidents that may occur within an organization such as this MOVEit cyber breach. This plan should not only highlight steps to recover from cyber-attacks but should also detail how to communicate with internal and external stakeholders

If you believe your data may have been impacted by this breach, the National Cyber Security Centre have issued guidance, available at https://www.ncsc.gov.uk/guidance/data-breaches

Brochure: secure+ from ramsac

secure+ is a proactive cybersecurity monitoring service designed to hunt for signs of malicious activity or potential cyberbreach, ramsac then takes action to prevent damage from being done.

Related Posts

  • Cyber Essentials: Transitioning from the Montpelier to Willow Question Set

    Cyber Essentials: Transitioning from the Montpelier to Willow Question Set

    Cybersecurity

    Cyber Essentials is evolving, on April 28, 2025, the Willow question set will replace Montpelier. Discover what’s changing, how it affects your certification, and how ramsac can help you [...]

    Read article

  • How to know if a Microsoft security alert is real

    How to know if a Microsoft security alert is real

    CybersecurityMicrosoft 365

    Microsoft security alert emails help you to know if someone is potentially trying to illegally access your Microsoft account. However, scammers and cybercriminals are well aware of this and [...]

    Read article

  • Infographic: Cybersecurity protection vs home protection

    Infographic: Cybersecurity protection vs home protection

    Cybersecurity

    Just like protecting your home requires more than a single lock, your business needs multiple layers of cybersecurity to stay resilient. Discover how home security principles apply to cyber [...]

    Read article

  • Hacker Misconceptions: The Good, The Bad, and The Grey

    Hacker Misconceptions: The Good, The Bad, and The Grey

    Cybersecurity

    When you hear the word hacker, you probably think of criminals in dark hoodies, but the reality is far more complex—some hackers protect us, some exploit us, and some [...]

    Read article

  • Social Engineering: The 7 most common tricks cybercriminals use (and how to stop them)

    Social Engineering: The 7 most common tricks cybercriminals use (and how to stop them)

    Cybersecurity

    Discover the top 7 social engineering tricks cybercriminals use to manipulate people into giving away sensitive information, and learn practical steps to protect yourself and your organisation from these [...]

    Read article

  • Protect your organisation with secure+ from ramsac

    Protect your organisation with secure+ from ramsac

    Cybersecurity

    Protect your organisation from evolving cyber threats with ramsac's secure+ A proactive monitoring solution designed to safeguard your systems, data, and reputation. [...]

    Read article

Quiz yourself

Are you more cyber savvy than an 11 year old?

11-14 year olds get asked these questions in school. Could you get these right?