Franklin Mint Federal Credit Union
bd_423f190687b39d3b · schema v1 · pii pii-v1
Full breach record for Franklin Mint Federal Credit Union →Franklin Mint Federal Credit Union (FMFCU) disclosed a data security incident involving the MOVEit Transfer software vulnerability. On June 1, 2023, FMFCU became aware of a CISA alert regarding a critical vulnerability in MOVEit. An investigation revealed that data belonging to FMFCU members may have been acquired without authorization. The breach date is listed as May 31, 2023. Affected data may include personal information, member numbers, and partial credit card numbers. FMFCU patched the system, engaged external experts, reported to law enforcement, and is offering 12 months of Experian IdentityWorks to affected members.
Linked disclosures
Why this link?Ransomware claims (2)
- bd_b80cb7caaa80cfabLeak Sitedispossessorfiled 2023-07-15(12d gap)Verified by operator
- bd_5df843afb3ea9231Leak Sitecl0pfiled 2023-07-10(17d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_30006f193fe4bd03Maine State AGfiled 2023-07-20(7d gap)Verified by operator
- bd_ad9fe53b1998dfdcMontana State AGfiled 2023-07-20(7d gap)Verified by operator
- bd_c86a8670fd179434Vermont State AGfiled 2023-07-20(7d gap)Verified
- bd_d7ad210f52856a5dDelaware State AGfiled 2023-07-20(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570959
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 27, 2023
- Raw hash
- fa225809025efa0aee57b4cd290114ec8a5b1c2c09add36feaf437eb3adebb57
Reporting entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Victim entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(56 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.