HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICLowContained
Broadview Federal Credit Union
bd_303f0e6d4f0868fe · schema v1 · pii pii-v1
Full breach record for Broadview Federal Credit Union →Broadview Federal Credit Union notified the NH Attorney General of a data security incident involving its vendor, Fiserv. An unauthorized actor exploited a vulnerability in Fiserv's MOVEit Transfer software to download files containing personal information of a limited number of Broadview members between May 27 and 31, 2023. Broadview was notified by Fiserv on November 3, 2023. Two New Hampshire residents were notified on November 30, 2023. Broadview offered complimentary identity protection services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_054fde74d4c97abfMaine State AGfiled 2023-11-30Candidate
- bd_d8c5f82f5b6b435fVermont State AGfiled 2023-11-30Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/broadview-federal-credit-union-20231130.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2023
- Raw hash
- 8232d1c96d31143e097e9b451571d18773ba3ed4fa02e9fd9d4adb660743bba8
Reporting entity
- Name
- Broadview Federal Credit Unionnorm: broadview federal credit union
Victim entity
- Name
- Broadview Federal Credit Unionnorm: broadview federal credit union
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- —
- Notification sent
- Nov 30, 2023
- Affected individuals
- 2
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General Consumer Protection Bureau
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.