HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSCVE-2023-34362LowContained
Financial Institution Service Corporation
bd_9fd9aa3388a492ce · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation reported a data breach affecting 14 Maine residents. The breach was a result of the MOVEit Transfer third-party event, which occurred on May 30, 2023, and was discovered the following day. The compromised information includes financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. Affected individuals were notified on October 9, 2023, and offered 12 months of identity monitoring and restoration services through Kroll.
Maine clockDiscovered May 31, 2023 → Filed with AG Oct 9, 2023131d ✗ ME AG >90d19 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 94 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_443bd0900c23f1b9Vermont State AGfiled 2023-10-09Verified
- bd_6e00e5b1fc258daeNew Hampshire State AGfiled 2023-10-09Verified
- bd_38cc1d86a1447377Vermont State AGfiled 2023-10-04(5d gap)Candidate
- bd_f28ceba937a62208New Hampshire State AGfiled 2023-10-04(5d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 17d gap
- bd_ab6b5f1c18375324Vermont State AGfiled 2023-09-28(11d gap)Candidate
- bd_3f02b20407b109deVermont State AGfiled 2023-09-22(17d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/5e384a87-d132-4513-81d5-0efd8ef92509.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 9, 2023
- Raw hash
- ec27ccfcdce863e8a987bd99b7cb8903fd2c8f47a200b3fc7f148382166cd1b6
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Oct 9, 2023
- Affected individuals
- 14
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- CVE references
Compliance
- Time to disclose
- 19 weeks(131 days from discovery to filing)
- Compliance flags
- ME AG >90d · 131dME resident >60d · 131dLeak >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 31, 2023→ Filed with AG: Oct 9, 2023131d 90 days ME AG >90d Maine Discovered: May 31, 2023→ Notified: Oct 9, 2023131d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.