HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Financial Institution Service Corporation
bd_38cc1d86a1447377 · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation (FISC) disclosed a data breach involving its MOVEit Transfer server, exploited via zero-day vulnerabilities in Progress Software's MOVEit tool. An unknown actor accessed the server between May 30-31, 2023, and exfiltrated data including names, SSNs, driver's licenses, and financial account numbers. FISC engaged forensic specialists, notified law enforcement, and provided 12 months of Kroll identity monitoring to affected consumers.
Vermont clock✗ VT AG >45 bday18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 89 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_f28ceba937a62208New Hampshire State AGfiled 2023-10-04Candidate
- bd_443bd0900c23f1b9Vermont State AGfiled 2023-10-09(5d gap)Verified
- bd_6e00e5b1fc258daeNew Hampshire State AGfiled 2023-10-09(5d gap)Verified
- bd_9fd9aa3388a492ceMaine State AGfiled 2023-10-09(5d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 12d gap
- bd_ab6b5f1c18375324Vermont State AGfiled 2023-09-28(6d gap)Candidate
- bd_3f02b20407b109deVermont State AGfiled 2023-09-22(12d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-10-04-financial-institution-service-corporation-progress-software-moveit-data-breach-notice
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 4, 2023
- Raw hash
- 860c0ddd3b38347fd0fd155e24b0a280f6900a1d1e0aabc5f449df02a38b640c
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Oct 4, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 ChannelT1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Promptly reported the event to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.