
Pennsylvania-based financial services company Franklin Mint Federal Credit Union said the personal and financial information of more than 140,000 individuals was compromised as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.Established in 1970, Franklin Mint Federal Credit Union (FMFCU) offers personal banking, business banking, and wealth management services to customers. The company operates approximately 17 branches across Southeastern Pennsylvania and employs over 350 people.In a recent filing with the office of the Attorney General of Maine, FMFCU said it suffered a cyber security incident after the Clop ransomware gang exploited a zero-day vulnerability in the MOVEit software.After being alerted by Progress Software on June 1, the company launched an investigation to understand the scope of the security incident.“After becoming aware of the alert, FMFCU took immediate steps to patch its MOVEit system in accordance with the software developer’s instructions. On June 19, 2023, the investigation revealed that data belonging to FMFCU members may have been acquired without authorization in connection with this issue,” FMCU said in a letter sent to affected individuals.“FMFCU then worked diligently to identify the potentially affected data elements and gather contact information needed to provide notice to all potentially affected members. This process concluded on June 28, 2023, at which time FMFCU took steps to arrange for individual notification,” it added.FMFCU identified that the compromised information included customers’ names, Social Security numbers, financial account numbers, and more. The company has reported to the state regulator that at least 140,963 individuals have been affected by the data breach.FMCU said it is providing a year of complimentary identity protection services, including credit monitoring and $1 million identity theft insurance, to all affected individuals and has set up a dedicated hotline via Kroll where people can call to resolve their queries.Around the same time, 1st Source Bank, a leading financial service company based in South Bend, Indiana, said it was also a victim of the zero-day vulnerability in the MOVEit Transfer web application.1st Source Bank said threat actors infiltrated its network on the 9th of July and accessed confidential information of some of its commercial and individual clients. It soon launched an internal investigation with assistance from cyber security experts to understand the nature of the compromised information.In a filing with the office of the Maine Attorney General, the financial services company said that the sensitive personal information of at least 450,000 individuals was compromised as a result of the security incident. The compromised information included names, dates of birth, Social Security Numbers, driver’s license, state identification card numbers, and other government identification numbers.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543