Umpqua Bank
bd_2976eb4a9bce87f5 · schema v1 · pii pii-v1
Full breach record for Umpqua Bank →Umpqua Bank, via vendor FIS, notified New Hampshire AG of a MOVEit Transfer zero-day exploit (T1190) affecting 50 state residents. Personal info (SSN, name) was accessed. FIS patched the system and notified law enforcement. Umpqua offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Begins
Jun 21, 2023
Discovered
Aug 18, 2023
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- Indiana State AGbd_3d603af54d5cb3992023-08-11 · +7dVerified
- California State AGbd_d3b7a25fe28a7b9b2023-08-11 · +7dVerified
- Maine State AGbd_d739cdfb0d8e16a82023-08-11 · +7dVerified
- Washington State AGbd_e9edd427ec1aee582023-08-11 · +7dVerified
Show 1 more filing ↓Show fewer ↑up to 52d gap
- SEC 8-Kbd_4d92681387db77792023-06-27 · +52dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jun 27, last Aug 18 (NH) — a 52-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.