Financial Institution Service Corporation
bd_6c9e179c96a550ba · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →10 incidents on fileFinancial Institution Service Corporation (FISC) notified South Carolina regulators of a breach involving the MOVEit Transfer tool. An unknown actor exploited zero-day vulnerabilities to access the server between May 30-31, 2023, exfiltrating names, addresses, and auto loan account numbers. FISC engaged forensic specialists, reported to law enforcement, and offered 12 months of Kroll identity monitoring. A specific count of Rhode Island residents (54) was noted.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
May 31, 2023
Discovered
Sep 29, 2023
Filed
vs. sector median
+9 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_868874c89834e55b2023-07-07 · +84dVerified by operator
Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_ee6604ed129e9a642023-09-22 · +7dVerified
- Montana State AGbd_f0522e8399768dcd2023-09-22 · +7dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 22 (MA), last Sep 29 (SC) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.