explain me their moveit breach? how many customers left because of the bridge? and what is the status of lawsuit?
Here is a breakdown of the MOVEit data breach, its surprisingly low impact on Progress Software's customer base, and the current status of the legal fallout as of 2026.
1. What was the MOVEit Breach?
The MOVEit breach, which began in May 2023, is considered one of the largest and most damaging cyberattacks in recent history.
How it happened: Progress Software owns a product called MOVEit Transfer, which is a "managed file transfer" (MFT) application. Thousands of government agencies, banks, hospitals, and major corporations use it to securely send massive files containing highly sensitive data (like payroll, medical records, and social security numbers).
A Russian-affiliated ransomware syndicate known as CL0P discovered a "zero-day" vulnerability in the software—specifically, a SQL injection flaw (CVE-2023-34362). Because it was a zero-day, Progress Software did not know the flaw existed. CL0P used this vulnerability to bypass authentication, install a secret backdoor (a web shell called LEMURLOOT), and quietly siphon massive amounts of data from underlying databases before Progress Software could issue a patch on May 31, 2023.
The Impact: Rather than encrypting systems, CL0P used a pure extortion strategy: they threatened to publish the stolen data on the dark web unless ransoms were paid. The breach impacted over 2,700 organizations globally (including the US Department of Energy, British Airways, and Shell) and exposed the highly sensitive personal data of more than 90 million individuals.
2. How many customers left because of the breach?
Surprisingly, almost none. Progress Software experienced virtually zero customer churn as a direct result of the breach.
In late 2023 and early 2024 earnings calls, Progress executives explicitly confirmed that customer retention for MOVEit remained completely stable. In fact, the product actually saw its Annual Recurring Revenue (ARR) grow by 17% in the quarters following the attack.
Cybersecurity analysts note a few reasons for this counterintuitive reality:
- Software "Stickiness": MOVEit is infrastructure software. It is deeply woven into the automated IT operations of massive enterprises. Ripping it out and replacing it with a competitor is incredibly expensive, time-consuming, and risky.
- The Nature of Zero-Days: Because it was an unknown zero-day flaw, and Progress Software issued patches rapidly upon discovering the unusual activity, many enterprise IT departments viewed it as an unavoidable industry hazard rather than gross negligence by Progress.
3. What is the status of the lawsuits? (As of mid-2026)
While Progress avoided customer churn, they—and the companies that used their software—are still dealing with a massive legal headache.
- The SEC Investigation (Resolved): Progress Software caught a major break from federal regulators. In August 2024, the Securities and Exchange Commission (SEC) concluded its fact-finding investigation into the breach and notified Progress that it would not pursue enforcement action against the company.
- The Class-Action Lawsuits (Ongoing): Progress Software is currently facing a massive, consolidated Multidistrict Litigation (MDL) class-action lawsuit in Massachusetts federal court. The plaintiffs (individuals whose data was stolen) allege Progress was negligent regarding industry-standard network safeguards and data retention policies. Because of the sheer size of the breach, this centralized litigation is highly complex and is still working its way through the courts.
- Downstream Customer Settlements (Happening Now): While Progress Software fights the main lawsuit, the downstream companies that used MOVEit are currently settling their own lawsuits with affected consumers and regional regulators. For example, in early to mid-2026, companies like Union Bank & Trust and Delta Dental agreed to multi-million dollar settlements for failing to properly secure or dispose of data that was stolen through the MOVEit vulnerability.