MOVEit
The MOVEit Customer Data Security Breach litigation was centralized before Judge Allison D. Burroughs in the District of Massachusetts in October 2023, consolidating claims arising from the mass exploitation of a software vulnerability in Progress Software's MOVEit file-transfer application, which a threat actor used to access data at a very large number of organizations worldwide that used the software to transfer sensitive files. With 236 pending actions, this is one of the largest and most structurally complex dockets currently active in the data-breach MDL category.
What makes MOVEit distinctive as a structural matter is that the vulnerability existed at the software-supply-chain level rather than within a single company's systems, meaning the affected population spans an unusually broad range of downstream institution types and sectors, each of which separately decided how and when to notify its own customers, patients, or members. Resolution risk in this docket is shaped by that multi-institution structure: claims may implicate both Progress Software's own security practices and the individual data-security and notification obligations of each downstream organization, adding layers of complexity beyond a typical single-defendant breach.
As one of the broader software-supply-chain breach events to generate a centralized federal MDL, this docket is a useful structural template for understanding how vulnerabilities in widely used enterprise software can generate litigation spanning far more institutions and sectors than a breach confined to one company's own systems. Criterica Intelligence's platform tracks this supply-chain breach pattern — distinguishing it from both single-company breaches and narrower vendor-breach structures — across every active MDL, since the scale and diversity of affected institutions materially shapes how duration and resolution risk should be assessed. A companion capital brief on this docket is available through Criterica Capital.
A vulnerability in Progress Software's MOVEit file-transfer application was exploited by a threat actor to access data at a very large number of organizations worldwide that used the software to transfer sensitive files.
Because the vulnerability existed in software used across many unrelated organizations and sectors, the breach cascaded through that shared dependency rather than originating within any single affected company's own systems.
Claims may implicate both the software vendor's own security practices and the individual data-security and notification obligations of each downstream organization that used the vulnerable software, adding complexity beyond a single-defendant breach.
That a vulnerability in widely used enterprise software can generate litigation spanning far more institutions and sectors than a breach confined to one company, a supply-chain pattern Criterica Intelligence tracks distinctly across the data-breach MDL landscape.
Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.