DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedFinancial accountFinancial credentialsCVE-2023-34362MediumContained

Financial Institution Service Corporation

bd_9fd9aa3388a492ce · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Oct 9, 2023

To disclose

19 weeks

Affected · nationwide

15,01214 in this filing

Linked

9 filings

Confidence

50%
Full breach record for Financial Institution Service Corporation10 incidents on file

Financial Institution Service Corporation reported a data breach affecting 14 Maine residents. The breach was a result of the MOVEit Transfer third-party event, which occurred on May 30, 2023, and was discovered the following day. The compromised information includes financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. Affected individuals were notified on October 9, 2023, and offered 12 months of identity monitoring and restoration services through Kroll.

Maine clockDiscovered May 31, 2023Filed with AG Oct 9, 2023131d ME AG >90d19 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 1 days
discovery → filing · 19 weeks / 131 days

May 30, 2023

Begins

May 31, 2023

Discovered

Oct 9, 2023

Filed

vs. sector median

+10 wks slower

This filing is one of 9 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 94 days.View originating leak claim

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filingsup to 17d gap

Filing propagation · 9 filings · 5 states

View merged incident ↗

Pattern: first filing Sep 22 (VT), last Oct 9 (ME) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.