British Airways, BBC and Boots were among the companies that were impacted by the breach that hit the software used by the UK payroll provider Zellis.
As a result of the cyberattack on Zellis, the personal data of employees at some of the largest companies in Britain has been compromised and exposed.
Zellis provides payroll support services to hundreds of companies in the UK. The cybersecurity incident occurred via one of their third-party suppliers called MOVEit.
British Airways stated that they have notified the colleagues whose personal information has been compromised to provide support and advice.
BBC is also aware of the data breach and are working closely with Zellis as they urgently investigate the extent of the breach.
MOVEit Transfer is a managed file transfer that is used by enterprises to securely transfer files using SFTP, SCP, and HTTP-based uploads.
The vulnerability is a SQL injection vulnerability which can be exploited by an unauthenticated attacker to gain unauthorized access to MOVEit Transfer’s database.
The vulnerability affects all MOVEit Transfer versions, but it doesn’t affect the cloud version of the product. The company also shared Indicators of Compromise (IoCs) for this attack and urges customers that notice any of the indicators to immediately contact its security and IT teams.
The instance of MOVEit Transfer managed by the payroll processor Zellis was used by the company to exchange files with tens of companies. So the number of impacted firms could be significant.
One of Zellis’s customers, the British health and beauty retailer and pharmacy chain Boots also confirmed to have been affected by the attack.
Airline Aer Lingus also confirmed that some of their current and former employee data has been disclosed.
Zellis published a statement that a small number of their customers have been impacted by this global issue and are actively working to support them. They had taken immediate action by disconnecting the server that utilizes MOVEit software and engaging an expert external security incident response team to assist with forensic analysis and ongoing monitoring.
The company have also reported the security breach to the ICO, DPC, and the NCSC in both the UK and Ireland.
Image Credits : The Economic Times














Comments