
Hospitality giant Choice Hotels said it suffered a significant cyber incident as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.The parent company of global hotel chain Radisson Hotels recently disclosed that it is one of the many organisations which used the Moveit Transfer web application to send and receive files securely.In a statement shared with the media, the company said, “Unfortunately, we have confirmed that MOVEit software, from our vendor, had a vulnerability that was exploited by bad actors, resulting in data breaches affecting many of their customers, including Radisson Hotels Americas.”While Choice Hotels is still in the process of determining the scope of the security incident, it said that it has “identified a limited number of guest records that were accessed by these bad actors.”“Choice Hotels takes cybersecurity and privacy very seriously. The integrity of our customers’ information is of the utmost importance, and significant resources are dedicated to continuously monitor the cyber landscape, including guidance from regulators, so that we can evaluate and adjust as needed,” it added.American National Insurance Company, one of the largest insurance providers in the U.S., also said that Progress Software is one of its service providers and the company has already launched an investigation to determine if any data has been accessed by the infamous Clop ransomware group.“On July 7, 2023, we became aware that American National’s name has been listed on a website outside the confines of the public Internet. We are working as thoroughly and expeditiously as possible to validate and review any data that may have been impacted to determine if any individuals’ or organizations’ information was involved,” the company told the media.“If we determine that an individual’s sensitive data was involved, we will provide notification to the individual along with resources to help protect their information,” it added.The U.S based real estate giant Jones Lang LaSalle also found itself on the list of almost 250 organisations that were affected by the global security incident. A source told TechCrunch that JLL has notified all 43,000 employees that their personal information has been compromised. The data breach, however, did not expose their social security numbers.“We were notified by MOVEit of a previously unknown security vulnerability in their software. Our immediate investigation detected unauthorized access to a limited number of files; we contained the malicious activity and patched our systems per vendor-provided instructions,” JLL spokesperson Allison Heraty said. “Our priority has been to communicate directly with those impacted as well as all relevant authorities, which we have done.”
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543