HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Franklin Mint Federal Credit Union
bd_abe5990bc5581add · schema v1 · pii pii-v1
Full breach record for Franklin Mint Federal Credit Union →Franklin Mint Federal Credit Union (FMFCU) disclosed a data security incident involving the MOVEit Transfer software vulnerability. FMFCU became aware of the CISA alert on June 1, 2023, and confirmed on June 19, 2023, that member data may have been acquired without authorization. Potentially affected data includes names, member numbers, partial credit card numbers, and personal loan information. FMFCU patched the system, quarantined it, reported to law enforcement, and offered 12 months of Experian IdentityWorks to affected members.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_567bc1186a84f6bcNew Hampshire State AGfiled 2023-07-21(1d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/FMFCU.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 20, 2023
- Raw hash
- 936cf4f65f061813c12e20f4cd410480f38f7d1e76177f46aae4d0296e90a2c6
Reporting entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Victim entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.