HackingStolen CredentialsSupply Chain (3P Vendor)TargetedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Savers Co-operative Bank
bd_3477cbf7767b60db · schema v1 · pii pii-v1
Full breach record for Savers Co-operative Bank →Savers Bank notified customers of a data security incident involving its third-party vendor, Progress Software (MOVEit), discovered on July 18, 2023. The incident exposed customer names, addresses, and bank account numbers. Savers Bank stated its own networks were not compromised and there is no evidence of misuse. Customers were advised to monitor accounts and place fraud alerts.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_b4cbb98b22f00984Vermont State AGfiled 2023-08-31Verified
- bd_7e91c3e2305447a4New Hampshire State AGfiled 2023-09-12(12d gap)Verified
- bd_9a7d4f190fec9454Maine State AGfiled 2023-09-12(12d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-31-savers-bank-progress-software-moveit-data-breach-notice-consumers-0
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 31, 2023
- Raw hash
- 000b2ed80e01a809c05aca6ea33de02963fd603c0237ab039535c84b74ddac22
Reporting entity
- Name
- Savers Co-operative Banknorm: savers co operative bank
- Domain
- saversbank.com
Victim entity
- Name
- Savers Co-operative Banknorm: savers co operative bank
- Domain
- saversbank.com
Incident
- Discovered
- Jul 18, 2023
- Materiality determined
- —
- Notification sent
- Aug 31, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.