DisclosureLens
HackingFinancial ServicesTechnologyFinanceVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Identity (basic)Government IDFinancial accountMediumContained

Financial Institution Service Corporation

bd_38cc1d86a1447377 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Oct 4, 2023

To disclose

18 weeks

Affected

Not disclosed

Linked

9 filings

Confidence

66%
Full breach record for Financial Institution Service Corporation10 incidents on file

Financial Institution Service Corporation (FISC) disclosed a data breach involving its MOVEit Transfer server, exploited via zero-day vulnerabilities in Progress Software's MOVEit tool. An unknown actor accessed the server between May 30-31, 2023, and exfiltrated data including names, SSNs, driver's licenses, and financial account numbers. FISC engaged forensic specialists, notified law enforcement, and provided 12 months of Kroll identity monitoring to affected consumers.

Vermont clock VT AG >45 bday18 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 1 days
discovery → filing · 18 weeks / 126 days

May 30, 2023

Begins

May 31, 2023

Discovered

Oct 4, 2023

Filed

vs. sector median

+10 wks slower

This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 89 days.View originating leak claim

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 12d gap

Filing propagation · 9 filings · 5 states

View merged incident ↗

Pattern: first filing Sep 22 (VT), last Oct 9 (ME) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.