Chevron Federal Credit Union, an Oakland-based not-for-profit financial institution, said it suffered a data breach after it became a victim of the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer web application.
In a recent filing with the Office of the Maine Attorney General, Chevron Federal Credit Union (CFCU)
said it used the MOVEit software to send and receive files securely and on 31st May 31, was notified by Progress Software, the manufacturer of the file transfer application, that the notorious Clop ransomware gang had exploited a zero-day vulnerability in the application.
CFCU immediately launched an internal investigation to understand the scope of the security incident.
“In late July, an independent cybersecurity firm published a previously unknown methodology that unauthorised parties had used to compromise the MOVEit application in various organisations, along with new detection approaches. In light of these new detection approaches, we reopened our investigation,” CFCU said.
“On August 1, 2023, we determined that an unauthorised party was able to decrypt and download some of the data in our MOVEit application by exploiting this vulnerability between May 30, 2023 and May 31, 2023.”
The compromised information included CFCU customers’ names and other personal identifiers such as social security numbers. The filing with the Office of the Maine Attorney General also confirms that more than 90,000 individuals were affected by the security incident.
While CFCU did not find any evidence of the compromised information being misused, the possibility of the same couldn’t be ruled out. The financial organisation is providing a year of complimentary credit monitoring and identity theft protection services through Experian IdentityWorks to all affected individuals whose data has been compromised in the security incident.
On 30th August, accident injury law firm Console & Associates, P.C.
said it is investigating the data breach reported by CFCU and will help affected customers of the financial institution assess how much they were impacted by the incident and help them claim compensation from CFCU proportionate to the damages they sustained.
Leading consumer rights law firm Cole & Van Note also
announced an investigation into the data breach suffered by CFCU, stating that it stands ready to help affected consumers claim just compensation proportionate to the damages they sustained.
CFCF is among more than 1,000 organisations worldwide that have suffered significant data breaches after the Clop ransomware gang exploited Progress Software’s MOVEit Transfer web application. According to German cybersecurity research firm KonBriefing, as of August 30, at least 1,011 organisations have
come forward about security incidents resulting from the exploitation of the software and at least 53.9 million individuals have been impacted by the same.
KonBriefing’s research also revealed that at least 838 American organisations have been impacted by the vulnerability exploitation till date.