DisclosureLens
HackingFinancial ServicesTechnologyFinanceStolen CredentialsData ExfiltratedCustomer Data InvolvedCredentialsPIIHighContained

CheckFree, a business unit of Fiserv, Inc.

bd_ee8a44c6cf0e5e5f · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Dec 12, 2008

To disclose

Affected

160,000scope not determined

Confidence

66%
Full breach record for CheckFree, a business unit of Fiserv, Inc.

Fiserv (via CheckFree business unit) notified New Hampshire AG regarding a Dec 2, 2008 incident where online bill payment traffic was redirected to a malicious site in Ukraine. Approximately 160,000 consumers were potentially exposed to malware attempting to steal credentials. Fiserv provided McAfee remediation and credit monitoring, and notified federal regulators including the FBI and FTC.

Incident timeline

Dec 2, 2008

Begins

Dec 12, 2008

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed160,000 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.