From Payroll to Personal Data
MOVEit 2023 supply chain hack via Zellis exposed BBC staff data, highlighting zero-day risk and third-party payroll vulnerabilities.
In June 2023, BBC employees learned their personal data was exposed through a breach at the payroll provider Zellis. Attackers exploited a newly discovered vulnerability in the MOVEit file transfer platform, accessed Zellis’s environment, and pulled staff records for clients that included the BBC, British Airways, and Boots. BBC core systems were not br…




