HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Rockland Trust Company
bd_3139885a81b4bbc9 · schema v1 · pii pii-v1
Full breach record for Rockland Trust Company →Rockland Trust Company notified customers of a data breach involving its MOVEit Transfer vendor, Progress Software Corporation. Unauthorized activity occurred May 27-31, 2023, exposing customer names, addresses, account numbers, emails, and bill payment details. Rockland Trust offered two years of Experian IdentityWorks monitoring. The vendor confirmed the vulnerability was contained and remediated.
Vermont clock⏱ VT AG >14 bday27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_6a20876f29df4b40Maine State AGfiled 2023-07-11(1d gap)Candidate
- bd_649f37004cf365dcMontana State AGfiled 2023-07-14(4d gap)Verified
- bd_ade58be497710be1Maine State AGfiled 2023-07-25(15d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-10-rockland-trust-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2023
- Raw hash
- c7e94883adbb1f4c97c0d81da047e55d109b9556ae479e732f0925a4e8bbe71f
Reporting entity
- Name
- Rockland Trust Companynorm: rockland trust
- Domain
- rocklandtrust.com
Victim entity
- Name
- Rockland Trust Companynorm: rockland trust
- Domain
- rocklandtrust.com
Incident
- Discovered
- Jun 13, 2023
- Materiality determined
- Jul 10, 2023
- Notification sent
- Jul 10, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with Vermont Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.