HackingVulnerability ExploitN-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Franklin Mint Federal Credit Union
bd_567bc1186a84f6bc · schema v1 · pii pii-v1
Full breach record for Franklin Mint Federal Credit Union →Franklin Mint Federal Credit Union (FMFCU) notified the NH AG of a data security incident involving the MOVEit Transfer vulnerability. FMFCU became aware of the CISA alert on June 1, 2023, and confirmed unauthorized data acquisition on June 19, 2023. Approximately 76 New Hampshire residents were affected. FMFCU patched the system, engaged forensic experts, notified law enforcement, and offered credit monitoring services.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_abe5990bc5581addDelaware State AGfiled 2023-07-20(1d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/franklin-mint-federal-credit-union-20230721.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 21, 2023
- Raw hash
- 5a08ccda62eceaed37cda67ba5fa473f1a8e88321ff4ca74c64eb0b31a51b53e
Reporting entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Victim entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- Jun 19, 2023
- Notification sent
- Jun 20, 2023
- Affected individuals
- 76
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(50 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.