DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedGovernment IDIdentity (basic)MediumContained

Crescent Bank

bd_255e1264a38fcb37 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Sep 28, 2023

To disclose

17 weeks

Affected

251state residents only

Confidence

66%
Full breach record for Crescent Bank

Financial Institution Service Corporation (FISC) notified New Hampshire residents that an unknown actor exploited zero-day vulnerabilities in the MOVEit Transfer server between May 30 and May 31, 2023, to exfiltrate data belonging to Crescent Bank members. Approximately 251 New Hampshire residents were affected. FISC reported the incident to federal law enforcement, provided credit monitoring via Kroll, and established a call center for affected individuals.

Incident timeline

undetected · 1 days
discovery → filing · 17 weeks / 120 days

May 30, 2023

Begins

May 31, 2023

Discovered

Sep 28, 2023

Filed

vs. sector median

+9 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed251 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.