HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Cadence Bank
bd_3a402a6f99ec3ecc · schema v1 · pii pii-v1
Full breach record for Cadence Bank →Cadence Bank disclosed a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer application. An unauthorized third party accessed and downloaded personal information, including names, addresses, SSNs, and financial account details, between May 28-31, 2023. Cadence learned of the vulnerability on June 1, 2023, and determined the scope of the breach by August 16, 2023. The bank implemented patches, engaged forensic investigators, notified law enforcement, and offered identity protection services to affected individuals.
California clockDiscovered Jun 1, 2023 → Notified Sep 15, 2023106d ✗ CA 60-day late15 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_9eeb910d8c5188afVermont State AGfiled 2023-09-15Verified
- bd_d1a549216a802d0fMontana State AGfiled 2023-09-15Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-573352
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2023
- Raw hash
- a0e290b0ed229cebe75f967ad84604ea63f776c9b0ac8a6b0349465389383da0
Reporting entity
- Name
- Cadence Banknorm: cadence bank
Victim entity
- Name
- Cadence Banknorm: cadence bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Sep 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software Corporation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- CA 60-day late · 106d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2023→ Notified: Sep 15, 2023106d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.