June 2023 opened with the crime already committed. Progress Software had disclosed the MOVEit Transfer zero-day on 31 May — the flaw later designated CVE-2023-34362 and rated 9.8 — but exploitation traced back to at least 27 May, over the US Memorial Day weekend, when security staffing was thinnest and attackers were exfiltrating data within minutes of compromise. Microsoft attributed the campaign on 4 June to the actor it tracks as Lace Tempest, operator of the Cl0p extortion brand. Cl0p posted its own statement on 6 June, giving victims until the 14th to negotiate.

The first wave surfaced on 5 June through a company most of its ultimate victims had never heard of: Zellis, a UK payroll provider. Through Zellis, the theft reached the BBC, British Airways, Boots and Aer Lingus. BBC staff were told national insurance numbers, dates of birth and home addresses may have been taken; British Airways warned employees about bank details. None of those organisations had made a decision about MOVEit. Their payroll provider had.

On 14 June, Cl0p began publishing names. On 15 June, CISA confirmed multiple US federal agencies were affected, and the Department of Energy said records were taken from two entities — Oak Ridge Associated Universities and the Waste Isolation Pilot Plant in New Mexico. CISA's director said the same day that no federal agency had received an extortion demand and no federal data had been leaked, and that this was not a systemic national-security threat on the scale of SolarWinds. Also on 15 June, Oregon's DMV disclosed a breach touching roughly 3.5 million licence and ID holders, and Louisiana's OMV one touching at least 6 million — close to ten million people between two state motor-vehicle agencies alone, people whose only relationship with the incident was having once been issued a driving licence.

Progress patched two further critical flaws in the same product during the month, on 9 and 15 June: three critical bugs in three weeks. Contemporaneous trackers ended June at roughly 130 organisations and about 15 million individuals — a count that would climb past 2,500 organisations and 64 million people by October, and keep rising into 2024.

Also that month · Replace, don't patch

Barracuda tells customers to throw the box away

On 6 June, Barracuda did something almost unheard of: it told customers that Email Security Gateway appliances compromised via CVE-2023-2868 must be physically replaced rather than patched, regardless of patch level. The flaw — a command-injection bug in attachment screening — had been exploited as a zero-day since at least October 2022; Barracuda spotted the malicious traffic on 19 May and shipped a patch on 20 May, then concluded the patch was not enough. Mandiant attributed the campaign to UNC4841, an espionage actor assessed to be operating in support of China, with government organisations over-represented among victims. The FBI later reinforced the guidance. A security vendor telling customers its product could not be remediated in place was a first, and a preview of the edge-appliance crises that dominate this archive's later years.

Also that month · The front door

Anonymous Sudan knocks Microsoft offline

Outlook.com went down on 7 June, OneDrive on the 8th, the Azure Portal on the 9th. Microsoft initially described only service degradation, then on 16 June attributed the disruption to Layer 7 DDoS activity by an actor it tracks as Storm-1359 — the group calling itself Anonymous Sudan — using HTTP floods and cache-bypass techniques from rented cloud infrastructure. Microsoft said it found no evidence customer data was accessed; a widely repeated $1 million payment demand is the attackers' claim. The group presented itself as Sudanese hacktivists, but in October 2024 US prosecutors charged two Sudanese brothers over an attack-for-hire operation tied to more than 35,000 DDoS attacks — hacktivism as a paid service, wearing a political costume.

India desk · June 2023

The CoWIN bot, and New Delhi's carefully worded denial

On 12 June 2023, the Malayalam outlet Fourth News reported that a Telegram bot was returning CoWIN vaccination-registration details — name, gender, date of birth, mobile number and identity-document numbers including Aadhaar, PAN, passport and voter ID — when queried with a phone number, bypassing the one-time password the official portal requires. Opposition politicians amplified it with screenshots of what they said was the data of serving Indian politicians, and demanded an independent inquiry.

The Health Ministry rejected the reports as "mischievous" and "without any basis", maintaining CoWIN data can only be retrieved with OTP authentication. The IT minister said CERT-In's initial finding was that the bot's backend was not directly querying CoWIN's APIs and appeared to be serving previously breached or stolen data. Read carefully, that is a denial of a fresh CoWIN compromise — not a denial that Indians' Aadhaar and passport numbers were circulating through a chat bot. CERT-In's full findings were never published. The bot was taken down, and on 22 June Delhi Police said they had arrested a man from Bihar and apprehended a minor, with reports indicating access came through a family member working as a health worker. Whatever the source, the episode established a pattern India would see repeatedly: the data is real, the breach is disputed, and the distinction offers citizens no protection at all.

⏳ Time capsule — June 2023

  • Apple unveiled the Vision Pro at WWDC on 5 June, priced at $3,499.
  • Thousands of subreddits went dark from 12 June in a coordinated protest over Reddit's new API pricing.
  • OceanGate's Titan submersible imploded on a dive to the Titanic on 18 June; debris was found on 22 June.
  • Wagner's Yevgeny Prigozhin seized Rostov-on-Don and marched on Moscow on 23–24 June, turning back under a brokered deal.
Where it stands today — 2026

The plumbing is the perimeter

MOVEit became the defining supply-chain breach of its era and, three years on, still the standard example of how one file-transfer product can reach thousands of organisations that never bought it. Its final toll passed 2,700 organisations and 90 million people. Cl0p's method — target the tools that move bulk data between institutions, steal rather than encrypt, extort at leisure — became the template that the same crew reused with Cleo in 2024 and that others copied through 2025. Barracuda's replace-don't-patch advisory, meanwhile, reads now as the opening entry in a long file that includes Ivanti in 2024 and F5 in 2025: the appliances sold to defend the perimeter are the perimeter's weakest point. And India's CoWIN affair set the template for a specific national frustration — an official denial that is technically accurate and practically useless.