HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedZero-DayIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Western Alliance Bank
bd_06380a907e1b2dce · schema v1 · pii pii-v1
Full breach record for Western Alliance Bank →Western Alliance Bank disclosed a data breach involving a third-party vendor's secure file transfer software. An unauthorized actor exploited an unknown vulnerability in the software to access Western Alliance's systems between October 12 and October 24, 2024, and exfiltrated files. The bank discovered the incident on January 27, 2025. Affected data includes names, Social Security numbers, and potentially financial account numbers, driver's license numbers, and tax identification numbers. The bank is offering one year of complimentary credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_1ff1a0aa9cf88a3eMaryland State AGfiled 2025-03-14Verified
- bd_31bf2692dfc20e2eMontana State AGfiled 2025-03-14Verified
- bd_72b6c4555f835088Maine State AGfiled 2025-03-14Verified
- bd_c53d68dc954452b4New Hampshire State AGfiled 2025-03-14Verified
Show 4 more filings ↓Show fewer ↑up to 109d gap
- bd_1e2bedd75bd91a03Washington State AGfiled 2025-06-30(108d gap)Verified
- bd_aa0c3c3710d65700Oregon State AGfiled 2025-06-30(108d gap)Verified
- bd_ca35ca5f0299f314New Hampshire State AGfiled 2025-06-30(108d gap)Verified
- bd_f8043b0f67779b8fTexas State AGfiled 2025-07-01(109d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-599939
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2025
- Raw hash
- 72037214a953a8aedcde2a6e77553d97ce55b0c153bd4569dfc9795e7b288543
Reporting entity
- Name
- Western Alliance Banknorm: western alliance bank
Victim entity
- Name
- Western Alliance Banknorm: western alliance bank
Incident
- Discovered
- Jan 27, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Third-party vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.