Financial Institution Service Corporation
bd_6e00e5b1fc258dae · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →10 incidents on fileFinancial Institution Service Corporation (FISC) reported a data breach involving the MOVEit Transfer server. An unknown actor exploited a zero-day vulnerability to access the server between May 30-31, 2023, and exfiltrated data. The breach affected approximately 10 New Hampshire residents affiliated with member financial institutions. FISC notified law enforcement, regulators, and affected individuals, offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
May 31, 2023
Discovered
Oct 9, 2023
Filed
vs. sector median
+10 wks slower
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- Vermont State AGbd_443bd0900c23f1b92023-10-09Verified
- Maine State AGbd_9fd9aa3388a492ce2023-10-09Candidate
- Vermont State AGbd_38cc1d86a14473772023-10-04 · +5dCandidate
- New Hampshire State AGbd_f28ceba937a622082023-10-04 · +5dCandidate
Show 4 more filings ↓Show fewer ↑up to 17d gap
- California State AGbd_6414ec0eb2b443b12023-09-28 · +11dVerified by operator
- Vermont State AGbd_ab6b5f1c183753242023-09-28 · +11dCandidate
- Delaware State AGbd_f567b7260ba921f02023-09-28 · +11dVerified by operator
- Vermont State AGbd_3f02b20407b109de2023-09-22 · +17dCandidate
Filing propagation · 9 filings · 5 states
View merged incident ↗Pattern: first filing Sep 22 (VT), last Oct 9 (NH) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.