DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Financial accountLowContained

Financial Institution Service Corporation

bd_6414ec0eb2b443b1 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Sep 28, 2023

To disclose

Affected

Not disclosed

Linked

9 filings

Confidence

65%
Full breach record for Financial Institution Service Corporation10 incidents on file

Financial Institution Service Corporation (FISC) disclosed a data breach resulting from the exploitation of zero-day vulnerabilities in the MOVEit Transfer tool provided by Progress Software Corp. An unknown actor accessed the server between May 30 and May 31, 2023, and exfiltrated data including names, addresses, and auto loan account numbers. FISC applied patches, engaged third-party cybersecurity specialists, reported the incident to federal law enforcement, and offered 12 months of identity monitoring via Kroll to affected individuals.

Leak gap clock Leak >30d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

May 30, 2023

Begins

Sep 28, 2023

Filed

This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 83 days.View originating leak claim

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 11d gap

Filing propagation · 9 filings · 5 states

View merged incident ↗

Pattern: first filing Sep 22 (VT), last Oct 9 (ME) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.