{"id":5741,"date":"2023-06-22T10:15:54","date_gmt":"2023-06-22T10:15:54","guid":{"rendered":"https:\/\/www.nebrcentre.co.uk\/?p=5741"},"modified":"2023-06-22T10:15:54","modified_gmt":"2023-06-22T10:15:54","slug":"moveit-file-transfer-breach","status":"publish","type":"post","link":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/moveit-file-transfer-breach\/","title":{"rendered":"MOVEit File Transfer Breach"},"content":{"rendered":"\n<p>The NCSC has released information about the MOVEit vulnerability, which has recently been exploited by criminals affecting Zellis, a market leader for payroll and HR solutions, impacting thousands of individuals and organisations.<\/p>\n\n\n\n<p>The stolen information from Zellis relates to employees at eight of Zellis&#8217;s customers, including the BBC, Boots and British Airways.<\/p>\n\n\n\n<p>Anyone who believes their information has been compromised as a result of this incident find out&nbsp;<a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/data-breaches\">how to protect themselves from the impact of the breach<\/a>.<br><br>If you are an organisation directly affected by this vulnerability, Progress (the vendor of the MOVEit software) has issued best practice&nbsp;<a href=\"https:\/\/community.progress.com\/s\/article\/MOVEit-Transfer-Critical-Vulnerability-31May2023\" target=\"_blank\" rel=\"noreferrer noopener\">advice on mitigating this vulnerability<\/a>.<\/p>\n\n\n\n<p>For further information on this situation please refer to the <a href=\"https:\/\/www.ncsc.gov.uk\/information\/zellis-incident\">NCSC webpage<\/a><\/p>\n\n\n\n<p>The NCSC offers extensive&nbsp;<a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/mitigating-malware-and-ransomware-attacks\">guidance on preventing and mitigating malware attacks<\/a>.<\/p>\n\n\n\n<p>Cyber attacks that target organisations&#8217; supply chains (rather than the organisation directly) are increasingly common. In addition to Supply Chain principles, the NCSC has recently provided:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\">\n<li><a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/mapping-your-supply-chain\">Guidance on how to map your supply chain<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ncsc.gov.uk\/collection\/assess-supply-chain-cyber-security\">Guidance on how to assess and gain confidence in your supply chain cyber security<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/www.ncsc.gov.uk\/blog-post\/new-cyber-security-training-packages-launched-to-manage-supply-chain-risk\">Free e-learning to help you manage cyber security risk across supply chains<\/a><\/li>\n<\/ol>\n\n\n\n<p>The NCSC&#8217;s position, along with law enforcement, is not to endorse, promote or encourage the payment of ransoms. If you would like the NEBRC to further explain any of the technical NCSC guides, please don\u2019t hesitate to reach out to us.<\/p>\n\n\n\n<p>The North East Business Resilience Centre is a police-led, not-for-profit organisation that provides 24\/7 cyber security support to SMEs within the region.<\/p>\n\n\n\n<p><strong>To discuss your business\u2019 cyber security needs contact the NEBRC today, and sign up <\/strong><strong>to receive the NEBRC\u2019s&nbsp;<\/strong><a href=\"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/core-membership-sign-up\/\">free core membership&nbsp;<\/a><strong>with the latest cyber security updates and access to a wealth&nbsp;of handy&nbsp;<\/strong><a href=\"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/resources\/\"><strong>resources<\/strong><\/a><strong>.&nbsp;<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The NCSC has released information about the MOVEit vulnerability, which has recently been exploited by criminals affecting Zellis, a market leader for payroll and HR&#8230;<\/p>\n","protected":false},"author":1,"featured_media":5742,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13],"tags":[],"class_list":["post-5741","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/posts\/5741","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/comments?post=5741"}],"version-history":[{"count":0,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/posts\/5741\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/media?parent=5741"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/categories?post=5741"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crcnetwork-cfkr6.projectbeta.co.uk\/northeastcrc\/wp-json\/wp\/v2\/tags?post=5741"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}