
The University of Missouri said it suffered a significant data breach as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.In a recent notice of data breach filed with the Office of the Attorney General of Maine, the University said that it used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application earlier this year.After being notified by Progress Software, the manufacturer of MOVEit software, the University of Missouri said it immediately applied the security patches released by the company and launched an internal investigation with assistance from third party cyber security experts to understand the scope of the incident.The investigation, which concluded on September 7, revealed that the sensitive personal information of the University’s current and former students and staff were compromised as a result of the incident. The affected information includes names and other personal identifiers along with Social Security Numbers.“The breach impacted some outside vendors that we use to assist in our operations, including our enrollment and pension processes. While we continue to work on obtaining specific information, we want to alert our employees, students and retirees that they might be impacted by this breach,” said Ben Canlas, interim vice president for Information Technology of the University.The filing with the regulator also confirms that at least 118,808 individuals were impacted by the data security incident.The university said that the exploitation of vulnerabilities in the MOVEit Transfer application also impacted two of its vendors - Pension Benefit Information, a subcontractor with several university vendors, and the National Student Clearinghouse, which is used to verify academic information and educational data reportingThe university has urged all of its former and current students and employees to remain vigilant and monitor their credit reports at a regular interval. Also, it is providing two years of complimentary Credit and CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and fully managed ID theft recovery services for individuals whose Social Security Numbers have been compromised in the data breach.“It is important to remember that even if every precaution is taken, individuals can still be the victim of a crime. Anyone who thinks they might be a victim of a crime, such as fraud or ID theft, is encouraged to file a police report,” the University added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543