HackingVulnerability ExploitSupply Chain (Dependency)Customer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSHigh
Financial Institution Service Corporation
bd_8bb15caef7090f5f · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation (FISC) reported a data breach affecting 237,678 individuals due to the MOVEit Transfer third-party vulnerability. The breach occurred on May 30, 2023, and was discovered on May 31, 2023. Exposed data includes names and financial account numbers with their associated access codes. FISC began notifying affected individuals on October 4, 2023, and offered 12 months of credit monitoring and identity restoration services through Kroll.
Maine clockDiscovered May 31, 2023 → Filed with AG Oct 4, 2023126d ✗ ME AG >90d18 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 89 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_27aaa54311703cb4California State AGfiled 2023-10-04Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/e3b3f59d-b2de-44be-92b5-cf78b7b622b0.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 4, 2023
- Raw hash
- c5ead6a3108104d246ea82d4c8d36ae8e26493174c0de4e9f83c1f0e2a3411ad
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Oct 4, 2023
- Affected individuals
- 237,678
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- ME AG >90d · 126dME resident >60d · 126dLeak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 31, 2023→ Filed with AG: Oct 4, 2023126d 90 days ME AG >90d Maine Discovered: May 31, 2023→ Notified: Oct 4, 2023126d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.