FIDELITY NATIONAL INFORMATION SERVICES, INC.
ent_019e44aa5af3420ec7b4dcc65f646055
Disclosures
15
SEC 10-K Item 1C · State AG · 7 jurisdictions
Incidents
5
filings grouped by incident
Max affected reported
793,626
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FIDELITY NATIONAL INFORMATION SERVICES, INC.
- Normalized
- fidelity national information— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6WQI0GK1PRFVBA061U48
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (15)newest first
- FEDERALSEC 10-K Item 1Cas victim2024-02-26
FIS Item 1C disclosure describes its cybersecurity risk management program, governance (CISO/CRO reporting to the Board Risk and Technology Committee), and the Cyber Fusion Center providing 24x7 monitoring. The filing explicitly states FIS has not identified any previous cybersecurity incidents that have materially affected, or are reasonably likely to materially affect, the company. No specific breach event is disclosed.
- 🐻California State AGas victim2023-11-09
Fidelity National Information Services (FIS) disclosed a data security incident involving a third-party service provider using Progress Software's MOVEit Transfer tool. On May 31, 2023, a previously unknown vulnerability (zero-day) in MOVEit was reported. An unauthorized third party accessed files containing personal information (name, financial account numbers, routing numbers, and paycheck amounts) of individuals conducting ACH transactions or receiving payroll via Republic Bank. FIS suspended the tool, patched the vulnerability, engaged forensics, and offered 12 months of identity monitoring to affected individuals.
- 🦞Maine State AGas reporting2023-10-06
Auto Club Trust, a financial services entity, reported an external system breach (hacking) occurring on May 27, 2023, discovered on August 8, 2023. The incident affected 46,033 individuals nationwide, including 24 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Fidelity National Information Services, Inc. (via outside counsel Morgan, Lewis & Bockius LLP) submitted the notice. Remediation included written notifications and 24 months of credit monitoring/identity theft restoration via ChexSystems.
- 🦫Oregon State AGas victim2023-10-04
Fidelity National Information Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-04. The breach occurred during 5/27/2023 - 5/31/2023. The breach was discovered on 7/12/2023. 793,626 individuals were affected. Notice was sent on 9/27/2023.
- 🐻California State AGas victim2023-10-04
Fidelity National Information Services, Inc. reported a data breach affecting H&R Block Emerald Card customers. A third-party service provider using Progress Software's MOVEit Transfer tool was compromised via a previously unknown vulnerability (zero-day) between May 27 and May 31, 2023. FNS became aware of the unauthorized acquisition on July 12, 2023. Affected data includes names, addresses, SSNs, DOBs, driver's license numbers, email addresses, phone numbers, and card account details. FNS suspended the tool, patched the vulnerability, and offered two years of identity monitoring.
- 🦬Montana State AGas victim2023-09-28
Fidelity National Information Services, Inc - Wayne Savings Community Bank reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-28. The breach occurred from 5/29/2023 to 5/31/2023. 1 Montana residents were affected.
- 🐻California State AGas reporting2023-09-19
Pension Benefit Information, LLC notified the California AG of a data breach involving its MOVEit Transfer software. An unauthorized third party exploited a vulnerability in Progress Software's MOVEit Transfer, accessing PBI's server on May 29-30, 2023, and downloading data. Affected data includes names and other data elements. PBI patched servers, investigated, and is offering credit monitoring via Kroll.
- 🦫Oregon State AGas victim2023-08-11
Fidelity National Information Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-11. The breach occurred during 5/27/2023 - 5/31/2023. The breach was discovered on 5/31/2023. 429,252 individuals were affected. Notice was sent on 8/11/2023.
- 🐻California State AGas reporting2023-08-11
Umpqua Bank notified California residents that their names and Social Security numbers were accessed due to a third-party vendor's exposure in the global MOVEit Transfer cybersecurity incident. The vendor uses Progress Software's MOVEit Transfer tool, which had a previously unknown vulnerability reported on May 31, 2023. The breach date is listed as May 27, 2023. Umpqua was notified by the vendor on June 21, 2023. No banking information was involved. The bank is offering 24 months of identity monitoring.
- 🌲Washington State AGas victim2023-08-11
Fidelity National Information Services, Inc. / Umpqua Bank, a finance sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-21 and filed notice on 2023-08-11. 145,274 Washington residents were affected. 51 days elapsed between awareness and notification.
- 🦬Montana State AGas victim2023-08-10
Fidelity National Information Services, Inc & Umpqua Bank reported a data breach to the Montana Attorney General. The breach was reported on 2023-08-10. The breach occurred from 5/29/2023 to 5/30/2023. 756 Montana residents were affected.
- 🦬Montana State AGas victim2023-07-21
Fidelity National Information Services, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-21. The breach occurred on 5/31/2023. 8 Montana residents were affected.
- 🌲Washington State AGas victim2023-07-17
Fidelity National Information Services, Inc. / Sound Community Bank, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-13 and filed notice on 2023-07-17. 13,795 Washington residents were affected. 34 days elapsed between awareness and notification. 13 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGas victim2023-07-17
Fidelity National Information Services, Inc reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-17. The breach occurred on 5/31/2023. 33 Montana residents were affected.
- 🌺Hawaii State AGas victim2007-07-04
Fidelity National Information Services, Inc. dba FIS reported a data breach to the Hawaii Office of Consumer Protection. The office was notified on 2007/07.04. Breach type: Data Theft by Employee or Contractor. 6,000 Hawaii residents were affected. Recovered from the Internet Archive after the notice was removed from the OCP table.