DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedPIIIdentity (basic)Financial accountLowContained

Franklin Mint Federal Credit Union

bd_423f190687b39d3b · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 1, 2023

Filed

Jul 27, 2023

To disclose

8 weeks

Affected

Not disclosed

Linked

10 filings

Confidence

65%
Full breach record for Franklin Mint Federal Credit Union2 incidents on file

Franklin Mint Federal Credit Union (FMFCU) disclosed a data security incident involving the MOVEit Transfer software vulnerability. On June 1, 2023, FMFCU became aware of a CISA alert regarding a critical vulnerability in MOVEit. An investigation revealed that data belonging to FMFCU members may have been acquired without authorization. The breach date is listed as May 31, 2023. Affected data may include personal information, member numbers, and partial credit card numbers. FMFCU patched the system, engaged external experts, reported to law enforcement, and is offering 12 months of Experian IdentityWorks to affected members.

Incident timeline

undetected · 1 days
discovery → filing · 8 weeks / 56 days

May 31, 2023

Begins

Jun 1, 2023

Discovered

Jul 27, 2023

Filed

vs. sector median

on median

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 7d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗
Maine State AGJul 20 · first
Massachusetts State AGJul 20 · first
Indiana State AGJul 20 · first
Delaware State AGJul 20 · first
Montana State AGJul 20 · first
Vermont State AGJul 20 · first
California State AG+7d · this page

Pattern: first filing Jul 20 (ME), last Jul 27 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.