CCleaner confirms data breach via MOVEit attack

Viking

Level 26
Thread author
Verified
Honorary Member
Top Poster
Well-known
Oct 2, 2011
1,553
CCleaner, a popular software for cleaning files and Windows Registry entries, has confirmed that attackers accessed some of its customer data.

Users on Windows and CCleaner forums started sharing emails that they received from the software maker informing them about a recent breach.

CCleaner said it was impacted by the MOVEit Transfer bug, which allowed attackers to exfiltrate some of its customers’ data.

“We recently discovered that as a customer of CCleaner, some limited personal information of yours was exposed on the dark web,” reads a message shared by a forum user.

However, after a user inquired if CCleaner did send such emails on the software community forum, one of the forum’s admins replied that it was a scam email and that users should ignore it.

We contacted CCleaner, and the company confirmed that it indeed sent out emails to affected individuals. The company told Cybernews that low-risk employee data, as well as some customer data, was impacted

“During continued due diligence, we found some of our customers’ personal information, such as name, email address and phone number, was also impacted,” the company said.

CCleaner’s representative said it will offer affected individuals complimentary dark web monitoring services.
 
Last edited by a moderator:

CyberDevil

Level 8
Verified
Well-known
Apr 4, 2021
360
Norton reported that my e-mail was shared through this attack ... Although I don't even remember having any account associated with ccleaner. I wonder how I can request free services now that I've been affected? :ROFLMAO:

By the way, F-Secure hasn't told me anything about my primary email being leaked yet.
 
F

ForgottenSeer 103564

Information is liquid gold. The lines between cyber criminals and legit business get blurred with this. Privacy is just a pipe dream on the internet. Can you stop privacy issues, short response, no. Can you control what services you use and what you divulge on the internet, yes.
 

Gandalf_The_Grey

Level 83
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,256
From Wilders:
I think it wasn't just CCleaner.

MOVEit Data Breach and Avast Customers
BreechGuard offer after MOVEIT app data breach

This is a article from June when Gen Digital (who own multiple brands, including Norton, Avast, LifeLock, Avira, AVG, ReputationDefender, and CCleaner.) disclosed they had been hit by MOVEit.

Norton parent firm Gen Digital, was victim of a MOVEit attack too
So, it seems that Avast customer data is also leaked.
 

Dark Knight

Level 5
Verified
Well-known
Aug 17, 2013
229
"For now, the company is offering affected users six months free of the BreachGuard dark web monitoring software"

So .... let me get this straight ... Avast software has a data breach on it's paid version of CCLeaner but yet , even though it is 6 months free, they are gonna offer BreachGuard, which is also owned by Avast , that will also nag you to buy it to monitor your information , which is pretty safe to say is PROBABLY already out there from the breach.

Seems kind of condescending of them

This is a company supposedly known for it's security software , yet they cannot even protect their own payment system ..... pfft, yea , that's something I want installed on my system . They can't even brand CCleaner with their name on it , they still have to use the Piriform name . otherwise people wouldn't buy it!

I don't know why people still believe in CCLeaner, the day Avast took it over is they day it went straight down the sh!tter.
 
Last edited:

Nevi

Level 12
Verified
Top Poster
Well-known
Apr 7, 2016
566
I downloadet Ccleaner from Piriforms own site yesteday, and Eset found dirt again. I never use Ccleaner again. I remember the data breach, but generally there has been too many problems with Ccleaner.
I thought you should know.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
Move to Privazer
What does Privazer solve that CCleaner and other data cleaners cannot?


i dont know why people still believe in system utilities, windows is capable of doing everyting itself , if you need separate program to clean up cookies, just use auto remove in exit in most browsers available
Marketing hype from the XP-era, when everyone used 5400 RPM HDDs and slower RAM.
 
Last edited:

Dark Knight

Level 5
Verified
Well-known
Aug 17, 2013
229
Isn't it caused by a MOVEit vulnerability! Why is everyone bashing CCleaner & Avast on this particular case? More than 100 companies and many more institutes were affected by it.
When a company known for security software gets caught with their pants down , it kind of speaks volumes about it's security capabilities. It don't really care how many other companies that were affected by this vulnerability , security companies should have the upper hand on things like this. It really is kind of embarrassing for them.
 

TuxTalk

Level 13
Verified
Top Poster
Well-known
Nov 9, 2022
604
When a company known for security software gets caught with their pants down , it kind of speaks volumes about it's security capabilities. It don't really care how many other companies that were affected by this vulnerability , security companies should have the upper hand on things like this. It really is kind of embarrassing for them.
This is not true, when the exploit is in the software of another company and this exploit will never be caught by any AV company, simply because its not a virus or malware.
So dont talk nonsense. The issue is with MoveIT and not with any company that uses its software, MoveIT is responsible for their own coding. So they need to patch or resolve or shut down.
 
  • Like
Reactions: [correlate]
F

ForgottenSeer 103564

When a company known for security software gets caught with their pants down , it kind of speaks volumes about it's security capabilities. It don't really care how many other companies that were affected by this vulnerability , security companies should have the upper hand on things like this. It really is kind of embarrassing for them.
Maybe users should look at articles like this and realize, that even large multi million dollar companies with great security have issues. If hackers want a target, they will pound at it and find a way. This kind of thing even happens to security suite companies as well.





These are just examples. Breaches, data stolen, hacks, they happen, often.
 

Nevi

Level 12
Verified
Top Poster
Well-known
Apr 7, 2016
566

Seandc33

Level 1
Sep 18, 2023
14
Isn't it caused by a MOVEit vulnerability! Why is everyone bashing CCleaner & Avast on this particular case? More than 100 companies and many more institutes were affected by it.
While I still agree with my take of it not looking good for Avast, the fact that it was a 0 day vulnerability should be mentioned too. There was no patch prior to the breaches.

My university was even affected by it, but I only got a notification that my email was harvested, not the password.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top