CSIDB logo
Incident

The Berwyn Group

Incident posture

Attack window
May 2023
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-07 12:20

Linked entities

Victim
The Berwyn Group
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack exploiting a vulnerability in Progress Software's MOVEit file transfer application impacted PBI Research Services along with numerous other entities globally, including federal and state governments, universities, healthcare organizations, and corporations. The incident allowed unauthorized access to private records belonging to a small percentage of the organization's clients that use the MOVEit administrative portal, though it did not compromise the company's core systems or software. PBI Research Services promptly patched its MOVEit instance, engaged cybersecurity and privacy specialists, notified federal law enforcement, and began contacting affected clients. The organization is working to notify and support impacted individuals whose personal information may have been exposed as a result of the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In late May 2023, Progress Software disclosed a cyberattack targeting its MOVEit file transfer application, a widely used managed file transfer platform. The vulnerability exploited in this campaign affected numerous organizations globally, including U.S. federal and state government agencies, universities, healthcare organizations, and corporations. Among the entities impacted by this incident was PBI Research Services, a company that utilized the MOVEit administrative portal for file transfers with a portion of its client base. The attack on PBI specifically involved unauthorized access to private records belonging to a small percentage of its clients, though the company emphasized that the breach did not extend to its core systems or proprietary software. PBI Research Services confirmed that its use of MOVEit was limited to administrative portal functionality with select clients, and the compromise was isolated to that specific application layer rather than broader infrastructure.

In response to discovering the cyberattack within its MOVEit environment, PBI Research Services took immediate remediation steps. The company promptly applied a patch to its MOVEit instance to address the exploited vulnerability. Following the patching, PBI assembled a specialized team of cybersecurity and privacy professionals to investigate the scope of the incident, assess the data potentially exposed, and coordinate remediation efforts. The organization also notified federal law enforcement authorities about the breach and initiated direct communication with the clients confirmed to be impacted by the unauthorized access. Throughout its public communications, PBI Research Services characterized the response as diligent and prioritized the privacy of both its clients and the individuals whose data was housed within the affected client systems.

The broader MOVEit cyberattack represented a significant supply chain and software vulnerability event affecting organizations across multiple sectors and geographies. As a file transfer application used by entities ranging from government agencies to private corporations, MOVEit served as a common point of compromise, allowing attackers to access data being transmitted or stored by client organizations. PBI Research Services' experience illustrates the downstream effects of such software-level vulnerabilities, where a flaw in a third-party application can result in data exposure for the application provider's clients and, by extension, the end consumers whose information those clients managed. The company's statement indicated that the attackers exploited the vulnerability in MOVEit to access private records without authorization, necessitating a coordinated notification process to inform affected parties.

Following the incident, PBI Research Services focused on supporting impacted clients in their notification and remediation obligations to affected individuals. The company indicated it was working closely with those clients to determine the specific records involved and to facilitate appropriate communications. The broader context of the MOVEit campaign placed affected organizations under obligations to notify regulators, clients, and in many cases, individual consumers whose personal information may have been exposed during the unauthorized file access. PBI's role as an intermediary service provider meant that the direct notification to affected individuals was conducted in coordination with its impacted client organizations rather than solely by PBI itself. The company reiterated that protecting client and consumer privacy remained its primary concern throughout the incident response process.

Sources

Sources available to members: 2 sources.

CSIDB