logo

Three Steps to Prevent a Cybersecurity Breach from MOVEit Exploit: SecurityScorecard’s investigation into Zellis reach uncovers 2,500 exposed MOVEit servers across 790 organizations

ID: 1869f9ea-a684-5a8f-8db7-3a439d3c73f3

STIX ID: report--1869f9ea-a684-5a8f-8db7-3a439d3c73f3

Feed Name: SecurityScorecard Blog

Threat Score
85/100

Date Published: 2025-10-28

Date Updated: 2026-04-29

...
...

The report describes a MOVEit SQL injection exploit used to breach payroll provider Zellis, resulting in remote code execution and large-scale data exfiltration attributed to the Cl0p ransomware gang; SecurityScorecard used Attack Surface Intelligence and NetFlow to identify over 2,500 exposed MOVEit servers (across 790 organizations), observed outbound transfers and web shell activity, and issues remediation guidance including removing vulnerable instances from the public Internet and restricting access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.