Financial Institution Service Corporation
bd_f0522e8399768dcd · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →10 incidents on fileFinancial Institution Service Corporation (FISC) notified Montana residents of a data breach involving the MOVEit Transfer tool. An unknown actor exploited zero-day vulnerabilities to access the server between May 30-31, 2023, exfiltrating names, SSNs, driver's licenses, and financial account data. FISC engaged forensic specialists, reported to law enforcement, and provided 12 months of Kroll identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
May 31, 2023
Discovered
Sep 22, 2023
Filed
vs. sector median
+8 wks slower
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_868874c89834e55b2023-07-07 · +77dVerified by operator
Regulatory filings (2) · sorted by filing gap
- Massachusetts State AGbd_ee6604ed129e9a642023-09-22Verified
- South Carolina State AGbd_6c9e179c96a550ba2023-09-29 · +7dVerified by operator
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 22 (MA), last Sep 29 (SC) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.