The earliest confirmed exploitation of the MOVEit Transfer zero-day is dated 27 May 2023. Memorial Day fell on Monday 29 May, which made 27–29 May a long American holiday weekend — thin staffing, delayed alerting, nobody reading dashboards. In observed cases attackers were exfiltrating data within minutes of compromise. Progress Software published its advisory and first patch on 31 May, confirming the flaw was already being exploited in the wild. The identifier CVE-2023-34362 was not assigned until 2 June.

The technique was a SQL injection in the MOVEit Transfer web application allowing unauthenticated access to the underlying database. Attackers dropped a web shell tracked as LEMURLOOT onto internet-facing servers and used it to enumerate and steal database contents — steal, not encrypt. That distinction is the campaign's real innovation, and the reason it dominated the year: Cl0p had worked out that encryption invites incident response, insurance claims and forensic scrutiny, while quiet mass theft invites a negotiation.

What makes the timeline genuinely unnerving is what came before it. Forensic work by Kroll later found the group had been testing MOVEit exploitation techniques as far back as July 2021, with further activity in April 2022. The zero-day was not discovered in May 2023; it was deployed in May 2023, having been held in reserve for as long as two years until a weekend arrived that suited them. That is not opportunism. It is inventory management.

The consequences belong mostly to June and beyond — the BBC, British Airways, US federal agencies, two state DMVs, and a final toll past 2,700 organisations and 90 million people. But the decision that produced all of it was made in the last five days of May, by someone consulting an American public-holiday calendar.

Also that month · Ten years in the open

Toyota's decade-long cloud exposure

On 12 May, Toyota disclosed that a misconfigured cloud environment had left data on roughly 2.15 million Japanese customers publicly accessible without a password — vehicle identification numbers, in-vehicle terminal IDs, and vehicle location data with timestamps. The exposure window ran from 6 November 2013 to 17 April 2023: a decade, almost to the day. A second disclosure on 31 May added roughly 260,000 further Japanese customers plus customers in other Asia-Pacific markets. Toyota blamed insufficiently thorough internal data-handling rules rather than any intrusion, and said it had no evidence of malicious use. Nobody attacked anything. A setting was wrong for ten years, and a car's location history is not a trivial thing to leave lying open.

Also that month · The disclosure wave

PharMerica, Sysco and the lag between breach and notice

May was heavy with disclosures of intrusions that had happened months earlier. PharMerica reported that an unknown third party had accessed its systems on 12–13 March, affecting approximately 5.8 million people including deceased patients — among the largest US health-data breaches of the year, with the Money Message group claiming the data. Sysco notified customers and employees of an intrusion that began on 14 January and was discovered on 5 March, exposing Social Security and driver's licence numbers. Discord disclosed that a third-party support agent's account had been compromised on 29 March. The pattern in each case: the harm was months old before the affected people were told.

India desk · May 2023

Silent assembly lines at Suzuki Motorcycle India

From 10 May 2023, production of motorcycles and scooters at Suzuki Motorcycle India's plant in Gurugram, Haryana was halted by what the company described as a cyberattack. The shutdown ran roughly a week, with Indian automotive trade reporting estimating a production loss of more than 20,000 two-wheelers. A spokesperson confirmed the company was aware of the incident and had promptly reported it to the concerned government department, declining further detail "for security purposes". The company postponed its annual supplier conference, due days later.

And then — nothing. No ransomware group publicly claimed it. Suzuki never confirmed any data theft. The vector remains undisclosed to this day. That silence is itself the story: an Indian manufacturing plant lost a week of output to a cyberattack about which the public record contains almost nothing, three years on. It is a useful corrective to the impression this archive can create that every incident produces a leak site, a CVE and a forensic report. Most do not. Most simply stop a factory, cost a fortune, and disappear.

⏳ Time capsule — May 2023

  • On 5 May the WHO declared that COVID-19 no longer constituted a public health emergency of international concern.
  • King Charles III and Queen Camilla were crowned at Westminster Abbey on 6 May, the first British coronation since 1953.
  • Nintendo released The Legend of Zelda: Tears of the Kingdom on 12 May.
  • On 16 May, OpenAI's chief executive testified before a US Senate subcommittee for the first time, proposing a licensing regime for powerful AI systems.
Where it stands today — 2026

The holiday-weekend playbook

May 2023 established two things that have never gone away. The first is operational: major campaigns launch on holidays and weekends, deliberately, and staffing rotas are now a security control rather than an HR matter — a lesson reinforced by every Christmas and Diwali campaign this archive has since recorded. The second is strategic: Cl0p's steal-don't-encrypt model, tested here and perfected through MOVEit, became the industry standard, and by June 2026 pure data-theft extortion had entirely overtaken ransomware as the dominant mode. Toyota's ten-year misconfiguration, meanwhile, remains the reference case for the harm that requires no attacker at all — and the reason cloud posture management became a product category rather than a checklist.