Financial Institution Service Corporation (FISC) disclosed a data breach resulting from the exploitation of zero-day vulnerabilities in the MOVEit Transfer tool provided by Progress Software Corp. An unknown actor accessed the server between May 30 and May 31, 2023, and exfiltrated data including names, addresses, dates of birth, Social Security numbers, driver's license numbers, and financial account information. FISC applied patches, engaged third-party cybersecurity specialists, reported the incident to federal law enforcement, and offered 12 months of identity monitoring via Kroll.