Change in Attack Tactics
The MOVEit attack marks an observable shift in attack tactics. Previous campaigns against Managed File Transfer (MFT) services, such as the exploitation of GoAnywhere MFT led by Clop, did result in data exfiltration but without any public indication of network encryption.
Now, a change can be observed: from the intentional compromise of entire network environments for the purpose of ransomware to the opportunistic exploitation of vulnerabilities for the unauthorized transfer of data. This highlights that attackers are exploiting vulnerabilities in a more flexible and targeted manner.
The solution lies in continuous quality assurance and prevention throughout the entire digital supply chain, as the security of a company relies heavily on external, interconnected factors.