A ransomware gang with links to Russia has claimed responsibility for the hack that led to British Airways, Boots and BBC staff potentially having their data stolen.
The group, called Clop, are Russian-speaking and said it was behind the stealing of information, which included bank account details and national security numbers.
According to the hackers, the vulnerability in MOVEit’s software had been exploited since 27 May.
Clop told Bleeping Computer that it had deleted any stolen data from governments, the military or children's hospitals.
Experts at Microsoft’s threat intelligence team linked Clop to the attacks said Clop exploited a zero-day vulnerability in file transfer software MOVEit.
"Microsoft is attributing attacks exploiting the CVE-2023-34362 MOVEit Transfer 0-day vulnerability to Lace Tempest, known for ransomware operations & running the Clop extortion site," the group’s intelligence team tweeted.
The hack involving BA, BBC and Boots staff was targeted at Zellis, a payroll solutions company, and was confirmed on Monday.
Zellis said a “small number of customers had been affected” and that “forensic analysis” was now taking place as part of the response to the attack.