DisclosureLens
HackingFinancial ServicesTechnologyFinanceVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedSupply Chain (3P Vendor)TargetedIdentity (basic)Government IDFinancial accountHighContained

Financial Institution Service Corporation

bd_464efdbae9f239d3 · schema v1 · pii pii-v1

Severity

High

Discovered

May 31, 2023

Filed

Sep 22, 2023

To disclose

16 weeks

Affected

2,140state residents only

Confidence

70%
Full breach record for Financial Institution Service Corporation10 incidents on file

Supplemental notice for Financial Institution Service Corporation (FISC) regarding a MOVEit Transfer zero-day exploit. Unauthorized access occurred May 30-31, 2023. Data exfiltrated included names, addresses, SSNs, driver's licenses, and financial account info. 2,140 Washington residents affected. FISC engaged forensic specialists, notified law enforcement, and provided 12 months of credit monitoring via Kroll.

Washington clock WA AG >90d16 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 1 days
discovery → filing · 16 weeks / 114 days

May 30, 2023

Begins

May 31, 2023

Discovered

Sep 22, 2023

Filed

vs. sector median

+8 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,140 affectedView incident
A leak claim by cl0p about this victim predates this filing by 77 days.View originating leak claim

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.