HackingVulnerability ExploitStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Western Alliance Bank
bd_1ff1a0aa9cf88a3e · schema v1 · pii pii-v1
Full breach record for Western Alliance Bank →Western Alliance Bank notified the Maryland AG of a data security incident affecting 11 Maryland residents. A threat actor exploited an unknown vulnerability in a third-party secure file transfer software between Oct 12-24, 2024, to access files containing names, SSNs, DOBs, financial account numbers, driver's licenses, and passports. WAB engaged forensic investigators, notified law enforcement, and is offering credit monitoring.
Maryland clock⏱ MD AG >30d7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_06380a907e1b2dceCalifornia State AGfiled 2025-03-14Candidate
- bd_31bf2692dfc20e2eMontana State AGfiled 2025-03-14Verified
- bd_72b6c4555f835088Maine State AGfiled 2025-03-14Verified
- bd_c53d68dc954452b4New Hampshire State AGfiled 2025-03-14Verified
Show 4 more filings ↓Show fewer ↑up to 109d gap
- bd_1e2bedd75bd91a03Washington State AGfiled 2025-06-30(108d gap)Verified
- bd_aa0c3c3710d65700Oregon State AGfiled 2025-06-30(108d gap)Verified
- bd_ca35ca5f0299f314New Hampshire State AGfiled 2025-06-30(108d gap)Verified
- bd_f8043b0f67779b8fTexas State AGfiled 2025-07-01(109d gap)Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376555.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 14, 2025
- Raw hash
- 1a95f6bc493adc6d9885d12fe25c0acb0a53d6907132ff13be71f801d7acd5e7
Reporting entity
- Name
- Polsinelli (on behalf of Western Alliance Bank)norm: polsinelli on behalf of western alliance bank
Victim entity
- Name
- Western Alliance Banknorm: western alliance bank
Incident
- Discovered
- Jan 27, 2025
- Materiality determined
- —
- Notification sent
- Mar 14, 2025
- Affected individuals
- 11
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Maryland Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(46 days from discovery to filing)
- Compliance flags
- MD AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.