Financial Institution Service Corporation
bd_27aaa54311703cb4 · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →10 incidents on fileFinancial Institution Service Corporation (FISC) disclosed a data breach resulting from the exploitation of zero-day vulnerabilities in the MOVEit Transfer tool provided by Progress Software Corp. An unknown actor accessed the server between May 30 and May 31, 2023, and exfiltrated data including names, addresses, dates of birth, Social Security numbers, driver's license numbers, and financial account information. FISC applied patches, engaged third-party cybersecurity specialists, reported the incident to federal law enforcement, and offered 12 months of identity monitoring via Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Oct 4, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Maine State AGbd_8bb15caef7090f5f2023-10-04Candidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.