MOVEit Transfer Under Siege: Massive 3,000% Spike in Attack Scans Signals Imminent Exploitation Campaign


# Surge in Cyberattacks Targeting MOVEit File Transfer Systems Raises Security Concerns

Cybersecurity experts are sounding the alarm about a dramatic increase in malicious scanning activity targeting Progress MOVEit Transfer systems, indicating potential preparation for large-scale cyberattacks.

## Sharp Increase in Scanning Activity

Threat intelligence firm GreyNoise has detected a significant spike in scanning attempts beginning May 27, 2025. The numbers tell a concerning story:

– **Before May 27**: Fewer than 10 scanning IPs detected daily
– **May 27**: Over 100 unique IP addresses
– **May 28**: 319 IP addresses
– **Current levels**: 200-300 IPs daily

Over the past 90 days, researchers have identified 682 unique IP addresses involved in this activity, with 449 observed in just the last 24 hours. Of these recent addresses, 344 are classified as suspicious and 77 as malicious.

## Global Threat Landscape

The scanning activity originates from multiple countries, with the highest concentration in:
– United States (majority)
– Germany
– Japan
– Singapore
– Brazil
– Netherlands
– South Korea
– Hong Kong
– Indonesia

## Active Exploitation Attempts

On June 12, 2025, GreyNoise detected actual exploitation attempts targeting two known MOVEit vulnerabilities:
– **CVE-2023-34362**: Previously exploited by Cl0p ransomware group in 2023, affecting over 2,770 organizations
– **CVE-2023-36934**: Another critical security flaw

## Why MOVEit is a Prime Target

MOVEit Transfer is a widely-used managed file transfer solution employed by businesses and government agencies to securely share sensitive data. Its popularity and access to high-value information make it an attractive target for cybercriminals.

## Essential Security Measures

Organizations using MOVEit Transfer should immediately:

1. **Block malicious IP addresses** identified in threat intelligence reports
2. **Update software** to the latest security patches
3. **Avoid public internet exposure** of MOVEit instances
4. **Monitor systems** for unusual activity

The surge in scanning activity suggests cybercriminals are actively searching for vulnerable MOVEit installations, making immediate protective action critical for organizations using this platform.

Share This Article