DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)Financial accountLowContained

Franklin Mint Federal Credit Union

bd_abe5990bc5581add · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 1, 2023

Filed

Jul 20, 2023

To disclose

7 weeks

Affected

Not disclosed

Linked

10 filings

Confidence

67%
Full breach record for Franklin Mint Federal Credit Union2 incidents on file

Franklin Mint Federal Credit Union (FMFCU) disclosed a data security incident involving the MOVEit Transfer software vulnerability. FMFCU became aware of the CISA alert on June 1, 2023, and confirmed on June 19, 2023, that member data may have been acquired without authorization. Potentially affected data includes names, member numbers, partial credit card numbers, and personal loan information. FMFCU patched the system, quarantined it, reported to law enforcement, and offered 12 months of Experian IdentityWorks to affected members.

Incident timeline

discovery → filing · 7 weeks / 49 days

Jun 1, 2023

Discovered

Jul 20, 2023

Filed

vs. sector median

1 wks faster

This filing is one of 10 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 7d gap

Filing propagation · 8 filings · 8 states

View merged incident ↗
Maine State AGJul 20 · first
Massachusetts State AGJul 20 · first
Indiana State AGJul 20 · first
Montana State AGJul 20 · first
Vermont State AGJul 20 · first
Delaware State AGJul 20 · first · this page

Pattern: first filing Jul 20 (ME), last Jul 27 (CA) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.