FIDELITY NATIONAL INFORMATION SERVICES, INC.
ent_efeedabfd2f4c282b0c552ea
Disclosures
14
State AG · 5 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
793,626
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- FIDELITY NATIONAL INFORMATION SERVICES, INC.
- Normalized
- fidelity national information— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6WQI0GK1PRFVBA061U48
- SEC EDGAR CIK
- 0001136893
- Domain
- fisglobal.com
Disclosure history (14)newest first
- New Hampshire State AGas reporting2023-11-27
FIS reported a data security incident involving its third-party vendor Progress Software's MOVEit Transfer tool. A zero-day vulnerability allowed an unauthorized third party to access files transferred from Webster Bank's client, the New Bedford Retirement Board. The incident affected 9 New Hampshire residents, exposing names and financial account/routing numbers. FIS disabled the tool, patched systems, and engaged law enforcement and forensic experts.
- California State AGas victim2023-11-09
Fidelity National Information Services (FIS) disclosed a data security incident involving a third-party service provider using Progress Software's MOVEit Transfer tool. On May 31, 2023, a previously unknown vulnerability (zero-day) in MOVEit was reported. An unauthorized third party accessed files containing personal information (name, financial account numbers, routing numbers, and paycheck amounts) of individuals conducting ACH transactions or receiving payroll via Republic Bank. FIS suspended the tool, patched the vulnerability, engaged forensics, and offered 12 months of identity monitoring to affected individuals.
- Maine State AGas reporting2023-10-06
Auto Club Trust, a financial services entity, reported an external system breach (hacking) occurring on May 27, 2023, discovered on August 8, 2023. The incident affected 46,033 individuals nationwide, including 24 Maine residents. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Fidelity National Information Services, Inc. (via outside counsel Morgan, Lewis & Bockius LLP) submitted the notice. Remediation included written notifications and 24 months of credit monitoring/identity theft restoration via ChexSystems.
- Oregon State AGas victim2023-10-04
Fidelity National Information Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-10-04. The breach occurred during 5/27/2023 - 5/31/2023. The breach was discovered on 7/12/2023. 793,626 individuals were affected. Notice was sent on 9/27/2023.
- California State AGas victim2023-10-04
Fidelity National Information Services, Inc. reported a data breach affecting H&R Block Emerald Card customers. A third-party service provider using Progress Software's MOVEit Transfer tool was compromised via a previously unknown vulnerability (zero-day) between May 27 and May 31, 2023. FNS became aware of the unauthorized acquisition on July 12, 2023. Affected data includes names, addresses, SSNs, DOBs, driver's license numbers, email addresses, phone numbers, and card account details. FNS suspended the tool, patched the vulnerability, and offered two years of identity monitoring.
- New Hampshire State AGas reporting2023-09-29
NorthEast Community Bank, via core processor FIS, disclosed a data security incident involving Progress Software's MOVEit Transfer tool. A zero-day vulnerability was exploited between May 31 and June 1, 2023, potentially exposing New Hampshire customers' names, addresses, and debit/ATM card numbers. FIS disabled the tool, patched systems, and engaged forensic experts. Three NH residents were notified on September 26, 2023, and offered two years of credit monitoring.
- Montana State AGas victim2023-09-28
Wayne Savings Community Bank notified customers of a data security incident involving a third-party vendor's MOVEit Transfer tool. The vendor exploited a previously unknown vulnerability (zero-day) in the software. Personal information including names, addresses, and account numbers was potentially accessed. No evidence of unauthorized use was found. The vendor patched the tool and offered 12 months of identity monitoring.
- New Hampshire State AGas reporting2023-09-15
Community Trust Bank, Inc. (CTBI) notified the NH AG of a data incident involving its service provider FIS and third-party vendor Progress Software's MOVEit Transfer. An unauthorized party exploited a zero-day vulnerability to access files containing customer PII (names, SSNs, etc.) on May 29-30, 2023. FIS discovered the breach on August 9, 2023. 6 NH residents are affected. Notifications and credit monitoring were offered.
- New Hampshire State AGas reporting2023-08-18
Umpqua Bank, via vendor FIS, notified New Hampshire AG of a MOVEit Transfer zero-day exploit (T1190) affecting 50 state residents. Personal info (SSN, name) was accessed. FIS patched the system and notified law enforcement. Umpqua offered 24 months of credit monitoring.
- Oregon State AGas victim2023-08-11
Fidelity National Information Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-08-11. The breach occurred during 5/27/2023 - 5/31/2023. The breach was discovered on 5/31/2023. 429,252 individuals were affected. Notice was sent on 8/11/2023.
- Montana State AGas victim2023-08-10
Umpqua Bank notified customers that their names and Social Security numbers were accessed via a third-party vendor's exposure in the global MOVEit Transfer cybersecurity incident. The vendor, which provides technology services to Umpqua, was notified of the vulnerability on May 31, 2023, and of the potential access on June 21, 2023. Umpqua is offering 24 months of identity monitoring.
- Montana State AGas victim2023-08-08
Community Trust Bank, Inc. notified customers of a data security event involving its service provider, FIS, and MOVEit Transfer software. A zero-day vulnerability in MOVEit was exploited by unauthorized actors between May 30 and July 30, 2023. Personal information was accessed. FIS discovered the access on July 24, 2023. Bank systems were not compromised. Credit monitoring offered.
- Montana State AGas victim2023-07-21
Valley Bank notified Montana residents of a data breach involving a third-party service provider's MOVEit system. Unauthorized access occurred between May 27-31, 2023, exploiting a vulnerability in the software. Affected data included names, addresses, SSNs, and loan numbers. The bank offered two years of free credit monitoring via ChexSystems.
- Montana State AGas victim2023-07-17
Sound Community Bank notified Montana residents of a potential data breach involving a third-party vendor's MOVEit file transfer system. The CL0P ransomware group exploited a vulnerability in MOVEit to access data uploaded on April 3, 2023. Affected data included names, SSNs, account numbers, and DOBs. The vendor patched the system on May 31, 2023. Bank offered 24 months of credit monitoring.
Supply-chain cascadesreviewed and confirmed
- FIDELITY NATIONAL INFORMATION SERVICES, INC.’s filing is one of at least 93 in the Progress Software Corporation supply-chain incident (2023).
Subsidiary disclosures (0)filed by group companies
◈ These filings were made by or about subsidiaries of FIDELITY NATIONAL INFORMATION SERVICES, INC. — not by FIDELITY NATIONAL INFORMATION SERVICES, INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
No disclosures on record for FIDELITY NATIONAL INFORMATION SERVICES, INC.’s tracked subsidiaries yet.