HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedTargetedPIIIDENTITY_BASICFINANCIAL_ACCOUNTMINORHighContained
Bank of New England
bd_027151ff29a3f5e4 · schema v1 · pii pii-v1
Full breach record for Bank of New England →Bank of New England notified the NH Attorney General of a data breach involving its third-party service provider, Fiserv. Unauthorized actors exploited a previously unknown vulnerability in MOVEit Transfer software between May 27-31, 2023, to access PII of 2,483 New Hampshire residents. Fiserv patched the vulnerability and offered two years of identity monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2,483 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bank-new-england-20240108.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 8, 2024
- Raw hash
- 945d01d0a7864f831727f163e6661ee97c69b0f4f0db1ddc33831bec36c9cdb0
Reporting entity
- Name
- Bank of New Englandnorm: bank of new england
Victim entity
- Name
- Bank of New Englandnorm: bank of new england
Incident
- Discovered
- Oct 20, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2,483
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTMINOR
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Federal Deposit Insurance CompanyNotified New Hampshire Banking Department
- Third party
- via Fiserv
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(80 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.