Deloitte disclosed on July 20 2026 that attackers accessed 12 million records through a compromised MOVEit instance. The breach occurred between June 28 and July 5. Affected data includes client financial documents and employee records.
The Clop group posted samples on their leak site on July 18. Deloitte stated no evidence of ransomware deployment on internal systems. The firm has notified regulators in 14 countries.
MOVEit vulnerabilities have been exploited since 2023. Deloitte had applied patches released in June 2026 but an unpatched server remained exposed.
Similar incidents hit other consulting firms in 2025. The company is offering two years of credit monitoring to impacted individuals.
Why this matters
The incident reinforces that even large professional services firms remain targets for supply chain attacks. Organizations must audit all third-party file transfer tools immediately.
Regulators are expected to propose stricter vendor risk rules by October 2026. Deloitte has begun migrating to alternative transfer platforms.