A file-transfer breach rarely produces one neat, predictable bill. The first visible costs may involve technical investigation and legal advice. Later come customer notifications, credit monitoring, regulatory work, litigation, insurance claims and the internal effort required to establish what was exposed.
Some incidents begin with a sophisticated attack against specialist transfer software. Others start with an ordinary spreadsheet, an inaccurate email address or an account that retained access for too long. Different causes, similar problem: sensitive information left the organisation without enough control around its destination, availability or contents.
The cases below show why secure file exchange needs to be assessed as a complete business process. Encryption matters, but so do patching, recipient identity, supplier oversight, data minimisation and the ability to reconstruct an exchange quickly.
MOVEit showed how one vulnerability can spread through thousands of organisations
In May 2023, Progress Software identified a previously unknown vulnerability in MOVEit Transfer and MOVEit Cloud. The flaw allowed unauthorised access to customer environments. CISA and the FBI reported that the CL0P group exploited internet-facing MOVEit applications to steal data.
The incident affected organisations using MOVEit directly and businesses exposed through service providers. Maximus, which used the platform for internal and external file sharing, reported that files containing personal information relating to an estimated 8 to 11 million people had been accessed. The company expected to offer notifications, credit monitoring and identity-restoration services, and initially estimated around $15 million in investigation and remediation expense.
The costs also travelled back to the software provider. Progress reported customer claims, government investigations and extensive private litigation. By November 2023, it was facing approximately 118 class actions connected to the incident. Investigation, legal and professional costs continued into 2024, although insurance recoveries reduced part of the direct expense.
A secure transfer platform can still create concentrated risk when a vulnerability provides access to many customers and large stores of sensitive files.
Lesson from the MOVEit incidentThe lesson is not that managed file transfer is inherently unsafe. The incident shows why organisations need a clear asset register, rapid patching, supplier communication, incident procedures and an understanding of which sensitive datasets sit inside each service.
Accellion exposed the cost of keeping an ageing transfer appliance in service
Attackers exploited vulnerabilities in the Accellion File Transfer Appliance during 2020 and 2021. CISA noted that the product was approaching end of life, with support due to end in April 2021.
One affected customer was the Washington State Auditor's Office. Files stored temporarily in its Accellion account were accessed by an unauthorised party. The affected unemployment-claim information may have included names, dates of birth, addresses, Social Security numbers and bank details.
The response involved forensic investigation, law-enforcement engagement, individual notifications, identity-theft protection and free credit monitoring. The Auditor's Office also began reviewing other tools and protocols for future file sharing.
A file does not need to be held permanently to become valuable to an attacker. Transfer staging areas, temporary repositories and forgotten exports should be included in retention, monitoring and supplier-risk reviews.
End-of-life technology is especially difficult to defend because security support, vendor fixes and architectural improvement become increasingly limited. Replacing it may feel disruptive, but a breach can force a hurried migration alongside notification, investigation and recovery work.
Human error can expose more data than the sender can see
In 2023, a Ministry of Defence spreadsheet was emailed to an external party for a legitimate operational purpose. Hidden data within the file meant that far more information was shared than the sender intended. Part of that information later appeared online.
The ICO described the potential harm to the affected Afghans as severe and said the resulting mitigations came at significant public expense. The incident demonstrates a stubborn weakness in spreadsheet-based exchange: the visible worksheet may not reveal hidden columns, tabs, formulas, comments or embedded information.
A much older ICO case involving Surrey County Council shows how a smaller mistake can still lead to enforcement. A staff member sent a file containing special-category information about 241 people to the wrong address. The file was not encrypted or password protected, and the council could not confirm whether every unintended recipient had destroyed it. The ICO issued a £120,000 penalty under the previous data-protection regime.
Technical controls cannot remove every sending error, although they can limit the consequences. Named-recipient access, authentication, expiry and revocation provide more options than an ordinary attachment that becomes an independent copy as soon as it reaches the inbox.
Breach costs accumulate through disruption and response
IBM's 2024 Cost of a Data Breach Report placed the global average breach cost at $4.88 million. It also found that 70% of the organisations studied experienced significant or moderate operational disruption. These are broad international benchmarks rather than a forecast for any one business, but they show where the financial pressure tends to build.
The graphic below is useful because it separates the direct financial figure from the operational time and disruption surrounding it.
Response costs continue after the initial containment work
The figures include a $4.88 million global average breach cost, 258 days to identify and contain a breach, and widespread operational disruption.
Where the cost commonly appears
- Investigation: Forensics, specialist advisers, legal support and analysis of affected files.
- Notification: Contacting customers, employees, regulators, insurers and commercial partners.
- Support: Call centres, credit monitoring, identity protection and complaint management.
- Disruption: Suspended services, manual workarounds, delayed projects and diverted staff.
- Longer-term exposure: Litigation, regulatory action, contract claims, insurance disputes and customer loss.
The strongest improvements sit around the full exchange
| Exposure seen in practice | Control to examine | Question for your organisation |
|---|---|---|
| A vulnerability affects a central transfer service. | Supplier assurance, patching and asset visibility. | Do we know which data and business processes depend on each provider? |
| Legacy technology remains internet facing. | Lifecycle and replacement planning. | Are unsupported or end-of-life systems still handling sensitive files? |
| A file contains more data than intended. | Data minimisation and pre-send review. | Can hidden content, metadata or unrelated records leave unnoticed? |
| A file reaches the wrong person. | Named access, authentication and revocation. | Can access be stopped after sending, or has a permanent copy already left? |
| The incident cannot be reconstructed quickly. | Transaction records and administrative oversight. | Can we identify the sender, recipient, file, access time and download activity? |
Organisations transferring large engineering, legal or media datasets also need an approved service that can handle the real workload. Otherwise, file-size limits create pressure to use unapproved platforms. A practical route to share large files securely can reduce that source of shadow IT.
How My MX Data supports a more controlled transfer process
My MX Data is a secure B2B file-exchange platform designed for controlled and auditable transfers between organisations. MX supports named-recipient access, multi-factor authentication, AES-256 encryption, configurable expiry settings and detailed transaction records.
These controls help administrators establish who was intended to receive a file, whether the recipient accessed or downloaded it and how long the information remained available. MX also supports large transfers without arbitrary file-size restrictions, helping teams stay within the approved process.
For highly sensitive data, ASR provides another protection method. ASR stands for Anonymise, Shard and Restore. It transforms the information so the original content is not recognisable, separates it into protected shards and restores it for an authorised recipient. ASR is separate from encryption and forms one part of a wider layered-security approach.
MX cannot remove the need for patching, supplier management, staff training or incident response. It provides an exchange-focused control layer for organisations that need stronger accountability once files move between customers, suppliers and partners. More detail is available in our guide to controlled B2B file exchange.
Find the cost before it becomes an incident
Choose a recent exchange involving personal information, intellectual property or confidential commercial material. Confirm which service handled it, who had access, whether the file contained hidden or unnecessary information and when access was due to close.
Then check the evidence. A dependable file audit trail should show enough activity to support investigation without relying on memory, screenshots or scattered email chains.
The expensive part of an insecure transfer often begins after the file has gone. Better recipient control, clearer records and a usable approved process cannot prevent every incident, but they can reduce exposure and make the response far less uncertain.