DisclosureLens
FEDERALItem 8.01 · voluntaryMalwareFinancial ServicesFinanceIdentity (basic)Government IDFinancial accountHealth (basic)CredentialsMediumContained

Tri Counties Bank

bd_1297d2dd698bf712 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 7, 2023

Filed

Oct 13, 2023

To disclose

35 weeks

Affected

Not disclosed

Linked

11 filings

Confidence

66%
Full breach record for Tri Counties Bank

Tri Counties Bank, a subsidiary of TriCo Bancshares, experienced a cybersecurity incident in February 2023 involving malware that prevented access to certain files on its internal network. The Bank took systems offline, engaged forensic investigators, and notified law enforcement and banking regulators. Its investigation determined that between February 7 and February 8, 2023 an unauthorized actor may have had access to systems storing sensitive customer and employee information, including Social Security numbers, financial account information and medical information. The Bank restored access to its internal systems after approximately one week, and potentially impacted individuals will be notified and offered 24 months of Experian IdentityWorks credit monitoring and credit restoration services at no cost.

Incident timeline

discovery → filing · 35 weeks / 248 days

Feb 7, 2023

Begins

Feb 7, 2023

Discovered

Oct 13, 2023

Filed

vs. sector median

+27 wks slower

This filing is one of 11 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 40d gap

Filing propagation · 10 filings · 7 states

View merged incident ↗
Maine State AGOct 12 · first
Montana State AGOct 12 · first
Indiana State AGOct 12 · first
Massachusetts State AGOct 12 · first
California State AGOct 12 · first
SEC 8-K+1d · this page

Pattern: first filing Oct 12 (ME), last Nov 22 (VT) — a 41-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.