HackingVulnerability ExploitData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIALLowContained
Franklin Mint Federal Credit Union
bd_d7ad210f52856a5d · schema v1 · pii pii-v1
Full breach record for Franklin Mint Federal Credit Union →Franklin Mint Federal Credit Union (FMFCU) disclosed a data security incident involving the MOVEit Transfer software vulnerability. On June 1, 2023, FMFCU became aware of a CISA alert regarding a critical vulnerability in MOVEit Transfer. An investigation revealed that member data, including names, member numbers, and partial credit card numbers, may have been acquired without authorization. FMFCU reported the incident to law enforcement, quarantined the affected system, patched the software, and offered 12 months of complimentary Experian IdentityWorks to affected members.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (2)
- bd_b80cb7caaa80cfabLeak Sitedispossessorfiled 2023-07-15(5d gap)Verified by operator
- bd_5df843afb3ea9231Leak Sitecl0pfiled 2023-07-10(10d gap)Candidate
Regulatory filings (4) · sorted by filing gap
- bd_30006f193fe4bd03Maine State AGfiled 2023-07-20Verified by operator
- bd_ad9fe53b1998dfdcMontana State AGfiled 2023-07-20Verified by operator
- bd_c86a8670fd179434Vermont State AGfiled 2023-07-20Verified
- bd_423f190687b39d3bCalifornia State AGfiled 2023-07-27(7d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/07/FMFCU.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 20, 2023
- Raw hash
- ea07ff98ff638674f9d80497649be3d24d9aaf0b6a8832ea65e079655107922b
Reporting entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Victim entity
- Name
- Franklin Mint Federal Credit Unionnorm: franklin mint federal credit union
- Domain
- fmfcu.org
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.