HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Financial Institution Service Corporation
bd_6e00e5b1fc258dae · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation (FISC) reported a data breach involving the MOVEit Transfer server. An unknown actor exploited a zero-day vulnerability to access the server between May 30-31, 2023, and exfiltrated data. The breach affected approximately 10 New Hampshire residents affiliated with member financial institutions. FISC notified law enforcement, regulators, and affected individuals, offering 12 months of credit monitoring.
Leak gap clock⏱ Leak >90d19 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 94 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_443bd0900c23f1b9Vermont State AGfiled 2023-10-09Verified
- bd_9fd9aa3388a492ceMaine State AGfiled 2023-10-09Candidate
- bd_38cc1d86a1447377Vermont State AGfiled 2023-10-04(5d gap)Candidate
- bd_f28ceba937a62208New Hampshire State AGfiled 2023-10-04(5d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 17d gap
- bd_ab6b5f1c18375324Vermont State AGfiled 2023-09-28(11d gap)Candidate
- bd_3f02b20407b109deVermont State AGfiled 2023-09-22(17d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/financial-institution-service-corporation-20231009.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2023
- Raw hash
- 36ad7a38b0c436d030ad0643222413cba117dadb2f143e7c17abf090fa28b767
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Sep 22, 2023
- Affected individuals
- 10
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- promptly reported the event to federal law enforcement and its primary federal regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 19 weeks(131 days from discovery to filing)
- Compliance flags
- Leak >90d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.