Crescent Bank
bd_255e1264a38fcb37 · schema v1 · pii pii-v1
Full breach record for Crescent Bank →Financial Institution Service Corporation (FISC) notified New Hampshire residents that an unknown actor exploited zero-day vulnerabilities in the MOVEit Transfer server between May 30 and May 31, 2023, to exfiltrate data belonging to Crescent Bank members. Approximately 251 New Hampshire residents were affected. FISC reported the incident to federal law enforcement, provided credit monitoring via Kroll, and established a call center for affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
May 31, 2023
Discovered
Sep 28, 2023
Filed
vs. sector median
+9 wks slower
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.