Financial services companies [1] [2], including TD Ameritrade [1], Charles Schwab [1] [2], and Prudential [1] [2], are facing class action lawsuits over a zero-day vulnerability breach in MOVEit software [1]. The lawsuits accuse the companies of failing to secure personally identifiable information (PII) and negligence in protecting customer data [1].


The breach, attributed to the Cl0p ransomware group [1], compromised sensitive financial data of numerous organizations [1], including Disney [1] [3], Chase [1], and British Airways [1]. Progress Software [1] [2], the developer of MOVEit [1] [2], is also facing a class action lawsuit for negligence and breach of contract [1]. The plaintiffs are seeking compensation for potential fraud and expenses incurred in securing their identities [1].

The class action lawsuits against financial services companies affected by the MOVEit zero-day vulnerability breach are demanding payment for 10 years of identity theft monitoring service, as stolen Social Security numbers cannot be replaced. The attacks on MOVEit servers by the Russian-speaking Clop group have impacted at least 49 million to 54 million individuals worldwide. Progress Software, the provider of MOVEit software, issued security patches to fix the flaw after the attacks. Multiple organizations, including government contractor Maximus and state government agencies, have reported data breaches due to the attacks. Lawsuits have been filed against organizations such as TIAA, Johns Hopkins University, CalPERS, and Progress Software. Prudential and Charles Schwab, along with its subsidiary TD Ameritrade, are the latest financial services giants to face lawsuits. Prudential notified over 320,000 individuals of their exposed personal data and offered them prepaid credit and identity theft monitoring services. A California resident has filed a complaint against Prudential, seeking damages and a security program overhaul. TD Ameritrade and Schwab notified over 61,000 individuals of their compromised personal information and offered them prepaid credit and identity theft monitoring services. A complaint has been filed against them, alleging negligence in protecting customer data and seeking unspecified damages.

Between June 2023 and the present day, over 600 data breaches occurred, affecting 40 million individuals worldwide due to the MOVEit Transfer vulnerability. Threat actors exploited this zero-day vulnerability to steal or erase healthcare information, educational records, financial records, personal information, Social Security numbers, and insurance details. The vulnerability was recently exploited on August 15, 2023, exposing the healthcare information of the Colorado Department of Health Care Policy and Financing (HCPF). The vulnerability allowed unauthenticated remote users to perform SQL injection attacks on MOVEit servers, granting them access to sensitive records. The breach affects primarily U.S.-based organizations, followed by companies in Germany, Canada, and the United Kingdom. Financial service-related organizations make up a significant portion of the affected hosts. The estimated cost of the breach is currently $9.9 billion, but it could potentially reach $65 billion if scaled.


