FEDERALItem 8.01 · voluntaryMalwareRansomwareData ExfiltratedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALSMediumContained
Tri Counties Bank
bd_1297d2dd698bf712 · schema v1 · pii pii-v1
Full breach record for Tri Counties Bank →Tri Counties Bank, a subsidiary of TriCo Bancshares, experienced a cybersecurity incident in February 2023 involving malware infection. The Bank took systems offline, engaged forensic investigators, and notified law enforcement. An investigation determined that an unauthorized actor accessed systems storing sensitive customer and employee data, including SSNs, financial accounts, and PHI. The incident is contained; affected individuals are receiving credit monitoring.
SEC clockMateriality determined Oct 12, 2023 → Filed Oct 13, 20231d ✓ SEC 4-day OK35 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_8a1c05db9a0376c6Leak Siteblack_bastafiled 2023-03-19(207d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_f2b2a26ac629eb7bCalifornia State AGfiled 2023-10-12(1d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/356171/000035617123000053/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 13, 2023
- Raw hash
- 8788780e9966972c8e4c5bf213997c39e3fd6f5cf10e0b69ca00a4cf4628cfbe
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- TriCo Bancsharesnorm: trico bancshares
- SEC CIK
- 0000356171
- Domain
- tricobank.com
Victim entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- Oct 12, 2023
- Notification sent
- Oct 13, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICCREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified banking regulators
Compliance
- Time to disclose
- 35 weeks(248 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 1d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Oct 12, 2023→ Filed: Oct 13, 20231d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.