HackingVulnerability ExploitCapture Stored DataZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Financial Institution Service Corporation
bd_f567b7260ba921f0 · schema v1 · pii pii-v1
Full breach record for Financial Institution Service Corporation →Financial Institution Service Corporation (FISC) notified Delaware AG of a data event involving the MOVEit Transfer tool. An unknown actor exploited zero-day vulnerabilities in May 2023 to access the server and exfiltrate data, including names, addresses, and auto loan account numbers. FISC patched the system, engaged third-party investigators, notified law enforcement, and provided 12 months of Kroll identity monitoring to affected individuals.
Leak gap clock⏱ Leak >30d17 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 83 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_868874c89834e55bLeak Sitecl0pfiled 2023-07-07(83d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_6414ec0eb2b443b1California State AGfiled 2023-09-28Verified
- bd_b6f3c5cb242f8acdDelaware State AGfiled 2023-09-28Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2023/10/Financial-Institution-Service-Corporation-Notice-of-Data-Event.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 28, 2023
- Raw hash
- 7aa697749be34ec8d620ed50f5552e6067fdc5ac15c47aeda2f4a2025ba034e1
Reporting entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Victim entity
- Name
- Financial Institution Service Corporationnorm: financial institution service
- Domain
- fiscdp.com
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the event to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 17 weeks(120 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.