MDL TrackerData Breach

MOVEit

MDL No. 3083  ·  U.S. District Court for the District of Massachusetts
MDL No.
3083
Docket Type
Data Breach
Transferee Judge
Hon. Allison D. Burroughs
Centralized
2023-10-04
Actions Pending
236
As Of
2026-09-01
Funding Considerations

This docket consolidates claims arising from the 2023 mass exploitation of a vulnerability in Progress Software's MOVEit file-transfer application, which attackers used to access data held by a very large number of organizations worldwide that relied on the software to move sensitive files, making it one of the broadest single-vulnerability data-breach events on record in terms of the number of downstream organizations and individuals affected. Centralized in the District of Massachusetts, the docket carries 236 pending actions, among the larger populations in the current data-breach MDL landscape.

For a funder, the MOVEit litigation's defining feature is its breadth: because the vulnerability was exploited across the software supply chain rather than at a single company, claims in this docket touch an unusually wide range of downstream institutions — from healthcare systems to government agencies to financial institutions — each with its own data-sensitivity profile and notification timeline. Diligence for any specific claim should identify which downstream MOVEit-using organization is implicated and what categories of data were exposed for that claimant, since the underlying software vulnerability is common but the specific harm varies considerably by institution.

As a data-exposure matter, medical-lien considerations apply only in the narrow sense that some affected downstream institutions were healthcare providers, though the claims themselves remain data-privacy and statutory-damages theories rather than medical-treatment claims. For a claimant group or firm with claims tied to a specific MOVEit-affected institution, Criterica Capital's commercial litigation finance line is the applicable structure, with diligence focused on that specific downstream relationship. A structural brief on this large, multi-institution docket is available through Criterica Intelligence.

Frequently Asked Questions
What made the MOVEit breach unusually broad?
+
Is there meaningful claim volume in this docket?
+
What diligence points matter most for a claim tied to this breach?
+
Do medical liens apply given that healthcare institutions were affected?
+

Pre-settlement funding is a non-recourse purchase of a portion of the proceeds of a pending legal claim — not a loan. If the case does not result in a recovery, nothing is owed. Rates, fees, and repayment terms are disclosed in full in the funding agreement, which the applicant’s attorney reviews before signing. Availability and terms vary by state.

Litigation structure and resolution-risk brief on Criterica Intelligence →
Holding MOVEit claims or inventory?
Send the details and our institutional team will respond within one business day.