HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Financial Institution Service Corporation
bd_6414ec0eb2b443b1 · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation (FISC) disclosed a data breach resulting from the exploitation of zero-day vulnerabilities in the MOVEit Transfer tool provided by Progress Software Corp. An unknown actor accessed the server between May 30 and May 31, 2023, and exfiltrated data including names, addresses, and auto loan account numbers. FISC applied patches, engaged third-party cybersecurity specialists, reported the incident to federal law enforcement, and offered 12 months of identity monitoring via Kroll to affected individuals.
Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_868874c89834e55bLeak Sitecl0pfiled 2023-07-07(83d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_b6f3c5cb242f8acdDelaware State AGfiled 2023-09-28Verified
- bd_f567b7260ba921f0Delaware State AGfiled 2023-09-28Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574338
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 28, 2023
- Raw hash
- c356545a4ef5db4d208016c3372d242c5cefc1f33d9b83065c6d25ed352cc345
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Reported the event to federal law enforcement
- Third party
- via Progress Software Corp.
- Initial access
- supply_chain
Compliance
- Compliance flags
- Leak >30d
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.