US govt contractor Serco discloses data breach after MoveIT attacks

Teilen:

Serco Inc, the Americas division of multinational outsourcing company Serco Group, has disclosed a data breach after attackers stole the personal information of over 10,000 individuals from a third-party vendor’s MoveIT managed file transfer (MFT) server.

In a breach notification filed with the Office of the Maine Attorney General, Serco said that the information was exfiltrated from the file transfer platform of CBIZ, its benefits administration provider.

“On June 30, 2023, Serco was made aware that our third-party benefits administration provider, CBIZ, experienced a ransomware attack and data breach,” the company explained.

“We understand from CBIZ that the incident began in May 2023 and CBIZ took steps to mitigate the incident on June 5, 2023. To be clear, the breach of CBIZ’s systems did not affect the safety and security of Serco’s systems.”

The personal information compromised in the attack includes any combination of the following: name, U.S. Social Security Number, date of birth, home mailing address, Serco and/or personal e-mail address, and selected health benefits for the year.

Serco is currently collaborating with CBIZ to investigate the breach and assess the full extent of the incident, focusing on ensuring that the third-party vendor has implemented security measures to prevent future incidents.

According to CBIZ, a cybersecurity firm is also conducting a thorough investigation into the matter.

Serco’s client roster includes a long list of U.S. federal agencies, including the Departments of Homeland Security, Justice, and State, as well as U.S. Intelligence Agencies and multiple U.S. Armed Forces branches (e.g., Navy, Army, Marine Corps, Air Force).

Serco is also a contractor for U.S. state and local governments and the Canadian government, and it also provides services to high-profile commercial customers such as Pfizer, Capital One, and Wells Fargo.

The company employs over 50,000 people across 35 countries and has an annual revenue of over $5,7 billion in 2022.

Clop gang behind the MoveIT hacks

The Clop ransomware gang initiated a large-scale data-theft campaign exploiting a zero-day vulnerability in the MOVEit Transfer secure file transfer platform starting May 27th.

On June 15, the cybercrime group began extorting organizations that fell victim to the data theft attacks, with the threat actors publicly exposing their names on their dark web data leak site.

The impact of these attacks is expected to extend to hundreds of companies worldwide, with many having already notified affected customers during the past two months.

Despite the many potential victims, Coveware estimates that only a few will likely give in to the Clop’s ransom demands.

Nevertheless, Clop is still projected to amass between $75-100 million after the payments due to their high ransom demands.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also revealed that several U.S. federal agencies have fallen victim to the attacks, as reported by CNN.

In addition, Federal News Network sagte that two U.S. Department of Energy (DOE) entities were also impacted.

 

(c) Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:52 pm, Juli 6, 2025
Wetter-Symbol 17°C
L: 16° | H: 18°
overcast clouds
Luftfeuchtigkeit: 71 %
Druck: 1007 mb
Wind: 9 mph NW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:51 am
Sonnenuntergang: 9:18 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
16° | 18°°C 0.99 mm 99% 13 mph 92 % 1015 mb 0 mm/h
Di. Juli 08 10:00 pm
Wetter-Symbol
13° | 24°°C 0.2 mm 20% 11 mph 76 % 1020 mb 0 mm/h
Mi. Juli 09 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 6 mph 66 % 1023 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
19° | 31°°C 0 mm 0% 8 mph 63 % 1024 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
20° | 30°°C 0 mm 0% 12 mph 54 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 72 % 1007 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0.31 mm 31% 8 mph 79 % 1007 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.99 mm 99% 10 mph 92 % 1009 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0.33 mm 33% 12 mph 53 % 1011 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 13 mph 37 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 10 mph 41 % 1013 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 7 mph 45 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 11 mph 49 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,896.70
1.21%
Ethereum(ETH)
€2,202.81
3.11%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.94
2.97%
Solana(SOL)
€129.97
3.90%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.146480
5.07%
Shiba Inu(SHIB)
€0.000010
4.09%
Pepe(PEPE)
€0.000008
5.44%
Nach oben scrollen