HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
City National Bank of Florida
bd_2df23e82ac6e9a13 · schema v1 · pii pii-v1
Full breach record for City National Bank of Florida →City National Bank of Florida notified consumers of a data breach stemming from a zero-day vulnerability in Progress Software's MOVEit Transfer application. Unauthorized access occurred May 29-30, 2023, resulting in the exfiltration of personal information including names, DOBs, SSNs, and bank account numbers. The bank engaged forensic experts, notified law enforcement, patched the vulnerability, and offered 24 months of identity theft protection services.
Leak gap clock✗ Leak >180d27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 573 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_5af843f65474ab40Maine State AGfiled 2023-06-30Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-30-city-national-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 30, 2023
- Raw hash
- 734651258e7a50eb3941c7cba1eb96e32b0d007208f06753d1a616e30d1c4239
Reporting entity
- Name
- City National Bank of Floridanorm: city national bank of florida
- Domain
- citynational.com
Victim entity
- Name
- City National Bank of Floridanorm: city national bank of florida
- Domain
- citynational.com
Incident
- Discovered
- Jun 3, 2023
- Materiality determined
- —
- Notification sent
- Jun 30, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- Leak >180dVT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.