Organisationsprofil
OrganisationProgress Software Corp - CSG is recorded as a company in US. Current public evidence covers 1 ASN, one supporting public reference; this is treated as an enterprise network resource-holder footprint, not a public carrier-connectivity or ou...
Die Entität befindet sich in der Mitte; ihre Kunden fächern sich nach links auf und ihre vorgelagerten Anbieter nach rechts (Pfeile zeigen die Transitrichtung). Zum Zoomen scrollen oder die Schaltflächen verwenden · den Hintergrund ziehen, um zu verschieben · auf einen Knoten klicken, um ihn im Verzeichnis zu öffnen.
Stand 2026-07
Die Entität befindet sich links; rechts fächern sich ihre Verbindungen nach Rolle auf. Der Graph zeigt die sichersten Verbindungen jeder Gruppe; die vollständige Liste darunter enthält jede Beziehung.
Die MOVEit-Kampagne 2023 begann mit einer ausgenutzten Zero-Day-Lücke, aber ihre weltweiten Folgen wurden durch eine längere Verantwortungskette bestimmt: Internetexposition, unvollständige Telemetrie, angesammelte Dateien, undurchsichtige Lieferantenwege und die langsame Identifizierung jeder Person, die in den gestohlenen Daten vertreten war.
Progress MOVEit is a risk and accountability case because the accountability issue is that managed transfer software is a relay of other peoples sensitive records, so the vendor and each operator must prove who knew what, when they knew it, and how quickly exposed files and customers were identified. The public record matters for employees, pension members, public agencies, vendors, students, patients, customers, insurers, and software buyers needed evidence that notification chains were not slower than the theft chain.
MOVEit Transfer was built for sensitive file exchange, which is why its 2023 exploitation campaign became more than a software vulnerability story. The incident turned a trusted transfer boundary into a disclosure path for public agencies, pension systems, schools, contractors, and enterprises that had delegated sensitive movement to a product and then had to prove what had crossed it.
The MOVEit campaign was not only a zero-day exploitation story. It showed how a managed file-transfer control plane can become a disclosure amplifier: exploitation began before the public patch, emergency advisories arrived in waves, operators had uneven telemetry and asset visibility, and every hour between compromise, patching, evidence preservation, and customer notification changed who could prove what had been taken.
The 2023 MOVEit campaign began with an exploited zero-day, but its worldwide consequences were determined by a longer accountability chain: internet exposure, incomplete telemetry, accumulated files, opaque supplier paths, and the slow work of identifying every person represented inside stolen data.