HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Broadview Federal Credit Union
bd_d8c5f82f5b6b435f · schema v1 · pii pii-v1
Full breach record for Broadview Federal Credit Union →Broadview Federal Credit Union notified Vermont AG of a data breach affecting a limited number of members. The incident resulted from a third-party vendor (Fiserv) compromise via the MOVEit Transfer vulnerability. Exposed data included names, addresses, and account numbers. No SSN or government IDs were compromised. Broadview offered 24 months of credit monitoring and identity theft protection.
Vermont clock⏱ VT AG >14 bday27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_054fde74d4c97abfMaine State AGfiled 2023-11-30Candidate
- bd_303f0e6d4f0868feNew Hampshire State AGfiled 2023-11-30Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-30-broadview-federal-credit-union-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 30, 2023
- Raw hash
- be3514a83d934f16a7a624d5c965e88d222afdcee5e174638b07cddd48a883af
Reporting entity
- Name
- Broadview Federal Credit Unionnorm: broadview federal credit union
Victim entity
- Name
- Broadview Federal Credit Unionnorm: broadview federal credit union
Incident
- Discovered
- Nov 3, 2023
- Materiality determined
- —
- Notification sent
- Nov 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.