Franklin Mint Federal Credit Union
bd_423f190687b39d3b · schema v1 · pii pii-v1
Full breach record for Franklin Mint Federal Credit Union →2 incidents on fileFranklin Mint Federal Credit Union (FMFCU) disclosed a data security incident involving the MOVEit Transfer software vulnerability. On June 1, 2023, FMFCU became aware of a CISA alert regarding a critical vulnerability in MOVEit. An investigation revealed that data belonging to FMFCU members may have been acquired without authorization. The breach date is listed as May 31, 2023. Affected data may include personal information, member numbers, and partial credit card numbers. FMFCU patched the system, engaged external experts, reported to law enforcement, and is offering 12 months of Experian IdentityWorks to affected members.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
Jun 1, 2023
Discovered
Jul 27, 2023
Filed
vs. sector median
on median
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitedispossessorbd_b80cb7caaa80cfab2023-07-15 · +12dVerified by operator
- Leak Sitecl0pbd_5df843afb3ea92312023-07-10 · +17dVerified by operator
Regulatory filings (7) · sorted by filing gap
- New Hampshire State AGbd_567bc1186a84f6bc2023-07-21 · +6dVerified by operator
- Maine State AGbd_30006f193fe4bd032023-07-20 · +7dVerified by operator
- Massachusetts State AGbd_62b1c6dd574948e62023-07-20 · +7dVerified
- Indiana State AGbd_773bee6d81ed25e82023-07-20 · +7dVerified
Show 3 more filings ↓Show fewer ↑up to 7d gap
- Delaware State AGbd_abe5990bc5581add2023-07-20 · +7dVerified by operator
- Montana State AGbd_ad9fe53b1998dfdc2023-07-20 · +7dVerified by operator
- Vermont State AGbd_c86a8670fd1794342023-07-20 · +7dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jul 20 (ME), last Jul 27 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.