HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Franklin Mint Federal Credit Union
bd_c86a8670fd179434 · schema v1 · pii pii-v1
Full breach record for Franklin Mint Federal Credit Union →Franklin Mint Federal Credit Union (FMFCU) disclosed a data breach stemming from the MOVEit Transfer vulnerability exploited by Progress Software. The incident, discovered June 1, 2023, resulted in unauthorized access to member data including names, SSNs, and partial credit card numbers. FMFCU patched the system, engaged forensic experts, and offered 12 months of Experian IdentityWorks to affected members.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_b80cb7caaa80cfabLeak Sitedispossessorfiled 2023-07-15(5d gap)Verified by operator
- bd_5df843afb3ea9231Leak Sitecl0pfiled 2023-07-10(10d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_30006f193fe4bd03Maine State AGfiled 2023-07-20Verified by operator
- bd_ad9fe53b1998dfdcMontana State AGfiled 2023-07-20Verified by operator
- bd_d7ad210f52856a5dDelaware State AGfiled 2023-07-20Verified
- bd_423f190687b39d3bCalifornia State AGfiled 2023-07-27(7d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-20-franklin-mint-federal-credit-progress-software-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 20, 2023
- Raw hash
- ed7e9f2ff67e1a0d4ea68145f7abc8b442d50f3ee229403aa64d6d76027f7b4c
Reporting entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Victim entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Jul 20, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.