HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedCREDENTIALSPIIHighContained
CheckFree, a business unit of Fiserv, Inc.
bd_ee8a44c6cf0e5e5f · schema v1 · pii pii-v1
Full breach record for CheckFree, a business unit of Fiserv, Inc. →Fiserv (via CheckFree business unit) notified New Hampshire AG regarding a Dec 2, 2008 incident where online bill payment traffic was redirected to a malicious site in Ukraine. Approximately 160,000 consumers were potentially exposed to malware attempting to steal credentials. Fiserv provided McAfee remediation and credit monitoring, and notified federal regulators including the FBI and FTC.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed160,000 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/fiserv-20081212.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2008
- Raw hash
- d5e245f9ad3274a3701b2cd103e305169faaeb04211adf616fec700588b673f1
Reporting entity
- Name
- FISERV, INC.norm: fiserv
- Domain
- fiserv.com
Victim entity
- Name
- CheckFree, a business unit of Fiserv, Inc.norm: checkfree a business unit of fiserv
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 160,000
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of InvestigationNotified the three major consumer reporting agenciesNotified the five principal federal financial institution regulatorsNotified the Federal Trade CommissionNotified the Securities & Exchange CommissionNotified the Commodities Futures Trading Commission
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.