Menu
Browse

Cyber Incident Victim: TomTom

Date:

May 2023

Location:

United States of America

Summary

The Clop ransomware gang exploited a vulnerability in Progress Software's MOVEit file-transfer tool, compromising TomTom among hundreds of organizations across multiple sectors. The Dutch navigation company confirmed unauthorized access occurred via its vendor's MOVEit platform, implementing security measures and notifying authorities, though the specific data impacted remains undetermined. This mass cyberattack affected financial institutions, healthcare providers, academic entities, and corporations, with hackers accessing sensitive information including personal identifiers, employee records, and commercial client data. The incident impacted over 17 million individuals collectively, with numerous organizations discovering compromised systems through Clop's dark web leak site and subsequent forensic investigations.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

The Clop ransomware gang exploited a previously unknown vulnerability in Progress Software's MOVEit file-transfer tool beginning in late May 2023, conducting mass data theft from corporate customers using the software. Dutch navigation company TomTom was among the victims listed on Clop's dark web leak site on June 5, 2023. TomTom confirmed the breach originated through their vendor's MOVEit platform, stating they became aware of the incident immediately after the vulnerability's disclosure. The company implemented undisclosed safety and security measures to protect data and notified relevant authorities, though the specific nature or volume of compromised information remained unconfirmed. This incident occurred amid a rapidly expanding wave of attacks affecting hundreds of organizations globally, with threat analysts estimating 270 victim organizations and over 17 million impacted individuals by early June.

Cyber Incident Image

The attack impacted multiple sectors including finance, healthcare, hospitality, and education. Radisson Hotels Americas reported limited guest record access, while real estate firm Jones Lang LaSalle confirmed unauthorized access affecting all 43,000 employees' non-Social Security Number data. 1st Source Bank disclosed theft of sensitive commercial and individual client PII in regulatory filings. UofL Health confirmed MOVEit exploitation at medical practices using the software but did not verify data access. TomTom's breach occurred through third-party file transfers via MOVEit, though the company maintained its internal systems remained secure. Clop systematically listed new victims on its leak site throughout June, with additional confirmed victims including Deutsche Bank, multiple universities, and pharmaceutical companies. TomTom joined organizations containing the incident by applying vendor-provided patches while forensic investigations continued across all affected entities to determine full breach scopes.

Sources
Sources available to members
1 source