HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
CITIZENS BANK
bd_0918409b8ec9c60c · schema v1 · pii pii-v1
Full breach record for CITIZENS BANK →Citizens Bank notified Vermont AG on 2024-09-26 of an incident where images containing customer PII (name, SSN, account number) were shared with an unauthorized party between Jan-Jun 2024. ~100 customers affected. Bank offered 2 years of TransUnion credit monitoring.
Vermont clock✗ VT AG >45 bday11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed100 affectedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-09-26-citizens-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2024
- Raw hash
- 6b247fcfaacb399796ca473253214de88c028dde3557aea02e08a01b8ff8d570
Reporting entity
- Name
- CITIZENS BANKnorm: citizens bank
- Domain
- citizensbank.com
Victim entity
- Name
- CITIZENS BANKnorm: citizens bank
- Domain
- citizensbank.com
Incident
- Discovered
- Jul 10, 2024
- Materiality determined
- Sep 26, 2024
- Notification sent
- Sep 26, 2024
- Affected individuals
- 100
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.