MOVEit Transfer Under Siege: Brace for a Cyberstorm!
A surge in scanning activity targeting MOVEit Transfer systems has been detected, suggesting a potential comeback tour of attacks. GreyNoise noted a jump in unique IPs on May 27, 2025, with numbers staying elevated. MOVEit Transfer, you might want to reconsider your security dance moves before the hackers start moshing.

Hot Take:
It seems like the MOVEit Transfer systems are the latest contestants in the “Hackers Got Talent” show, and the judges (a.k.a. cybercriminals) are buzzing in with enthusiasm. With unique IPs scanning like they’re auditioning for a cyber opera, it’s time for MOVEit to MOVEit or lose it!
Key Points:
- There’s been a significant spike in scanning activity targeting MOVEit Transfer systems, starting May 27, 2025.
- GreyNoise detected up to 682 unique IPs involved in this surge, with Tencent Cloud leading the charge.
- The bulk of these scanners are based in the US, hinting at a coordinated effort rather than random attacks.
- Historical context: Clop ransomware gang previously exploited MOVEit vulnerabilities in 2023.
- Two SQL injection vulnerabilities have been spotted, but no widespread exploitation has occurred yet.
Already a member? Log in here