Insights

CL0P: why your file-transfer systems deserve a security review

CL0P’s MOVEit attacks highlight the risks facing file-transfer systems. Discover how firewall rules reviews, patching and security testing help UK businesses reduce exposure and protect sensitive data.

Plainsight Security consultant reviewing firewall access rules and file-transfer security to identify unnecessary exposure of sensitive business data.

File-transfer platforms often hold valuable business information and need to communicate with customers or suppliers. CL0P’s exploitation of MOVEit Transfer demonstrates why these systems deserve close attention, from application security and patching to the firewall rules controlling access.

For UK businesses, the practical question is simple: do you know which systems exchange your sensitive data, who can reach them and how they are protected?

Who is CL0P?

CL0P, also written as Clop, is a cybercriminal operation associated with ransomware and data extortion.

In June 2023, the FBI and CISA published an advisory describing CL0P’s exploitation of internet-facing MOVEit Transfer applications. Attackers installed a malicious web shell called LEMURLOOT and used it to steal data from underlying databases.

The exploited vulnerability, CVE-2023-34362, was a SQL injection flaw that could allow an unauthenticated attacker to access the application’s database.

This was a vulnerability in a particular product. The broader lesson applies wherever a business exposes an application that stores or processes sensitive information.

Why file-transfer systems are attractive targets

Businesses need to exchange documents. Depending on the organisation, these may include payroll records, customer information, financial reports, contracts or intellectual property.

A file-transfer platform can therefore combine three important characteristics:

  • Valuable information passes through it.
  • External organisations need access.
  • It may connect to other business systems.

Calling a product a “secure file-transfer platform” does not remove the need to manage its security. The application, hosting environment, accounts and network access all require attention.

The first step is knowing what you use. File transfers may take place through a dedicated server, a cloud service, a supplier portal or an application introduced by an individual department.

Data theft can cause damage without encryption

Ransomware discussions often focus on files becoming inaccessible. However, stolen information can create serious consequences even when business systems remain operational.

Backups can help restore lost or encrypted data. They cannot retrieve information an attacker has already copied.

For file-transfer systems, security planning should therefore address confidentiality as well as availability. Consider what information is stored, how long it remains there and who can access it.

Would a firewall have prevented the MOVEit attack?

A firewall controls permitted network traffic. A conventional network firewall does not necessarily detect an application vulnerability inside an allowed connection.

If a public-facing file-transfer service legitimately accepts HTTPS traffic, malicious requests may arrive through the same permitted route as normal customer activity.

A firewall review should not be presented as a guaranteed defence against SQL injection or an unknown application flaw. Its value is in establishing whether the exposure is necessary and whether access is appropriately restricted.

For example:

  • Does the service need to be reachable from the whole internet?
  • Could access be limited to known partners?
  • Is the management interface exposed unnecessarily?
  • Can the file-transfer server reach unrelated internal systems?
  • Are old or temporary access rules still active?

Where public access is necessary, application security and monitoring remain essential.

What should your business check?

AreaPractical question
System ownershipWho is responsible for each file-transfer platform?
Internet exposureWhich interfaces are publicly reachable, and why?
UpdatesWho monitors vendor advisories and applies urgent fixes?
Firewall rulesAre permitted sources, destinations and services restricted appropriately?
Network separationIs the platform separated from sensitive internal systems?
AccountsAre administrator, user and service-account permissions proportionate?
Data retentionAre transferred files removed when no longer needed?
LoggingCan suspicious access and unusual downloads be investigated?
SuppliersDo you know which providers handle your information and how they notify you of incidents?
Incident responseCan access be restricted quickly without losing essential evidence?

These questions also apply when a supplier operates the platform. Establish which responsibilities belong to your organisation and which belong to the provider.

Patching needs a clear owner

Urgent security updates are difficult to manage when everyone assumes someone else is responsible.

For each platform, identify who receives security notifications, who approves emergency changes and who verifies that remediation is complete.

A patching process should also cover situations where a fix is unavailable. Depending on vendor guidance and business requirements, temporary measures may involve restricting access or taking an affected service offline.

If exploitation is suspected, installing a patch alone does not establish that the attacker’s access has been removed. Investigation and recovery should follow the relevant vendor and incident-response guidance.

How independent security assessments help

Different assessments examine different parts of the risk.

Firewall rules review

A firewall rules review examines the agreed configuration and permitted access. It can identify unnecessarily broad rules, exposed management services, obsolete exceptions and weaknesses in network separation.

It helps answer: are we allowing more access than the business needs?

External infrastructure penetration testing

External testing assesses the agreed internet-facing infrastructure. It can investigate exposed services, configuration weaknesses and exploitable vulnerabilities.

It helps answer: what could an attacker achieve against our external systems?

Web application penetration testing

Application testing examines security within the agreed application scope, including authentication, access controls and input handling.

It helps answer: could application functionality be used to access information or perform actions without authorisation?

Routine vulnerability scanning

Scheduled scanning helps identify detectable known vulnerabilities and configuration issues as systems change.

It provides useful recurring visibility, but it does not guarantee discovery of an unknown flaw or replace urgent action on a vendor security advisory.

Start with the systems handling your data

You do not need to use MOVEit to benefit from the lessons of the CL0P campaign.

Identify the platforms exchanging your sensitive information. Confirm their owners, review their exposure and check whether their network access matches their purpose.

Plainsight Security provides independent firewall rules reviews, penetration testing and routine vulnerability scanning.

If you are unsure what your firewall allows, or whether your file-transfer systems are exposed unnecessarily, contact us to discuss an independent review.

Portrait of Plainsight Security's lead tester

Written by

Mark Tomlinson

Our lead penetration tester, Mark Tomlinson, holds The Cyber Scheme Team Leader qualification in infrastructure penetration testing, an advanced certification recognised by the National Cyber Security Centre (NCSC) and used by professionals testing government systems and UK critical national infrastructure. Mark is also registered with the UK Cyber Security Council as a Principal Cyber Security Professional (PriCSP) specialising in Security Testing and holds an MSc in Computer Science with Cyber Security.

More about how we work
Talk to a tester

Put this into practice.

Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.

← All insights