Could You Be Affected by the Boots Employee Data Breach?

If you were employed by Boots on or before June 2023, your data might have been compromised in the MOVEit data breach.

Join the Claim isn’t a law firm. We connect you with regulated UK firms that run group action claims. If one of our partner firms takes this case forward, we’ll share more details, including how to check your eligibility.
Join the Claim Limited is a claims management company. This claim is not regulated by the Financial Conduct Authority. Join the Claim Limited is authorised and regulated by the FCA (FRN: 1053404) for regulated claims management activities only.

Quick & Simple

Register your interest

Stay Informed

Get justice

Overview

In June 2023, a cyber-attack affected businesses around the world. 

Hackers targeted Zellis, a payroll provider used by Boots, by exploiting a flaw in a widely used file transfer tool called MOVEit.

As a result of the hack, personal PAYE details belonging to current and former Boots staff were exposed.

The compromised data included employee: 

  • Names and Titles
  • Employee Numbers
  • Dates of Birth
  • Emails
  • Partial Home Addresses
  • National Insurance Numbers 
  • Home Address (partial)  
  • Employment Start and End Dates 

At least one UK law firm is now investigating a potential group claim on behalf of affected Boots employees.

We are monitoring the situation closely. Register your interest and we’ll keep you updated if one of our regulated UK partner law firms is able to take this claim forward. 

Boots data breach – At a glance  

Status

Stay Informed

What do we know about the Boots employee data breach?

  • Criminals exploited a vulnerability in the MOVEit file transfer app, which is used by thousands of organisations around the world.
  • The breach affected payroll provider Zellis, – which used MOVEit.
  • Zellis provided payroll support services to Boots.
  • The data breach affects current and former Boots staff – who were employed on or before June 2023.
  • The criminals behind the data breach are thought to belong to the ‘Clop’ Russian crime group.   

How Join the Claim works​

Quick survey

Take a moment to answer a few simple questions so we can understand your connection and keep you updated.

Register interest

Share your details so we can keep you informed if any updates become available.

Join a claim

If a partner law firm takes this claim forward, we’ll let you know the next steps and how to join.

Frequently asked questions

Zellis, a third-party payroll provider used by Boots experienced a data breach when hackers exploited a vulnerability in a popular file transfer tool called MOVEit. As a result, the personal information of many Boots employees may have been accessed by hackers. This includes names, dates of birth, National Insurance numbers, and bank details.

The breach could have exposed sensitive information like your name, contact details, date of birth, employee number and National Insurance number.

A group action claim allows people affected by the same issue to take action together. This strength in numbers helps stand up to big organisations. Join the Claim helps connect people with law firms so these actions have real impact.

At Join the Claim, we bring consumers and law firms together to ensure these group actions are as powerful as possible.

We are not a law firm. Our role is to keep people informed about potential group actions if one of our regulated UK partner law firms is able to take this claim forward.  

No. Registering simply means you’ll receive updates. If a law firm later takes on the case, you’ll be given the option to learn more about the process and any potential costs before deciding whether to take part. 

No. You are free to contact a solicitor directly at any time if you would like legal advice or wish to explore a claim.

When you register your interest with Join the Claim, we’ll keep you updated if one of our regulated partner law firms decides to take the claim forward. However, other law firms may also investigate or pursue claims independently of Join the Claim.

Registering for updates does not prevent you from speaking to another law firm or joining a claim elsewhere.

Latest updates on the Boots employee data breach

  • July 2026

    There have been no significant public developments relating specifically to Boots since the company notified affected employees. Investigations and potential legal claims relating to the MOVEit/Zellis cyber attack continue.

  • June 2023

    Zellis, the payroll provider used by Boots, confirms it has been compromised by the cyberattack. Shortly after the breach, Boots begins contacting employees whose data may have been compromised. This includes current and former staff. The company confirms that personal and payroll data was affected.

    Cybersecurity experts link the attack to the Russian ransomware group Clop (also known as C10p), which had exploited the MOVEit vulnerability across multiple global organisations.

  • May 2023

    Hackers exploited a vulnerability in the MOVEit file transfer app. Progress Software, which owns the app, admitted the data hack.

We’ll provide more updates on the Boots employee data breach as they occur.  

Join the claim
Join the claim
Join the claim

Who could be affected by the Boots employee data breach?

If you were employed by Boots on or before June 2023, your data might have been compromised.

Register to stay updated and we’ll let you know if a partner law firm takes this claim forward.

Rated Excellent


on REVIEWS.io

Rated Excellent on REVIEWS.io

Join the claim
Clifford
Very easy to sign up, hope its sorted soon
Susan
Very easy and quick to complete the claim Everything was explained well and fees payable in etc were made very clear
Peter
So easy to sign up for the claim

Latest MOVEit data breach news