DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIdentity (basic)MediumContained

Stockman Bank of Montana

bd_353f8ae784f3b6b8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 31, 2023

Filed

Aug 8, 2023

To disclose

10 weeks

Affected

4,581state residents only

Linked

5 filings

Confidence

66%
Full breach record for Stockman Bank of Montana

Stockman Bank notified customers of a cybersecurity incident involving its vendor, Progress Software. A vulnerability in the vendor's MOVEit file-sharing software was exploited by unauthorized individuals, leading to the exfiltration of personal information (names and other PII) from a small percentage of Stockman Bank customers. The bank engaged forensic investigators, secured its systems, and offered one year of complimentary credit monitoring via Experian IdentityWorks.

Incident timeline

discovery → filing · 10 weeks / 69 days

May 31, 2023

Discovered

Aug 8, 2023

Filed

vs. sector median

+1 wks slower

This filing is one of 5 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Indiana State AGAug 7 · first
Montana State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.