Financial Institution Service Corporation
bd_6414ec0eb2b443b1 · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →10 incidents on fileFinancial Institution Service Corporation (FISC) disclosed a data breach resulting from the exploitation of zero-day vulnerabilities in the MOVEit Transfer tool provided by Progress Software Corp. An unknown actor accessed the server between May 30 and May 31, 2023, and exfiltrated data including names, addresses, and auto loan account numbers. FISC applied patches, engaged third-party cybersecurity specialists, reported the incident to federal law enforcement, and offered 12 months of identity monitoring via Kroll to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Sep 28, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Vermont State AGbd_ab6b5f1c183753242023-09-28Candidate
- Delaware State AGbd_f567b7260ba921f02023-09-28Verified by operator
- Vermont State AGbd_38cc1d86a14473772023-10-04 · +6dCandidate
- New Hampshire State AGbd_f28ceba937a622082023-10-04 · +6dCandidate
Show 4 more filings ↓Show fewer ↑up to 11d gap
- Vermont State AGbd_3f02b20407b109de2023-09-22 · +6dCandidate
- Vermont State AGbd_443bd0900c23f1b92023-10-09 · +11dVerified
- New Hampshire State AGbd_6e00e5b1fc258dae2023-10-09 · +11dVerified
- Maine State AGbd_9fd9aa3388a492ce2023-10-09 · +11dCandidate
Filing propagation · 9 filings · 5 states
View merged incident ↗Pattern: first filing Sep 22 (VT), last Oct 9 (ME) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.