HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Financial Institution Service Corporation
bd_b6f3c5cb242f8acd · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation (FISC) notified Delaware AG of a data event involving the MOVEit Transfer tool. An unknown actor exploited zero-day vulnerabilities (May 30-31, 2023) to access the server and exfiltrate customer data, including names, addresses, and auto loan account numbers. FISC patched the system, engaged forensic specialists, notified law enforcement, and offered 12 months of Kroll identity monitoring. The incident is contained.
Leak gap clock⏱ Leak >30d17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 83 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_868874c89834e55bLeak Sitecl0pfiled 2023-07-07(83d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_6414ec0eb2b443b1California State AGfiled 2023-09-28Verified
- bd_f567b7260ba921f0Delaware State AGfiled 2023-09-28Candidate
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/10/Financial-Institution-Service-Corporation-Notice-of-Data-Event.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 28, 2023
- Raw hash
- de773796abf6fed3107a0628113bdde91cb818812a5e7195cf0bfd7055e266fe
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- promptly reported the event to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(120 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.