Cadence Bank
bd_3a402a6f99ec3ecc · schema v1 · pii pii-v1
Full breach record for Cadence Bank →3 incidents on fileCadence Bank disclosed a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer application. An unauthorized third party accessed and downloaded personal information, including names, addresses, SSNs, and financial account details, between May 28-31, 2023. Cadence learned of the vulnerability on June 1, 2023, and determined the scope of the breach by August 16, 2023. The bank implemented patches, engaged forensic investigators, notified law enforcement, and offered identity protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
Jun 1, 2023
Discovered
Sep 15, 2023
Filed
vs. sector median
+6 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitedispossessorbd_955b68cfd2f4b2942024-04-19 · +217dVerified by operator
- Leak Sitecl0pbd_904e886fa624bb042023-07-06 · +71dVerified by operator
Regulatory filings (4) · sorted by filing gap
- Vermont State AGbd_9eeb910d8c5188af2023-09-15Verified by operator
- Massachusetts State AGbd_b9c2b0baae525a492023-09-15Verified by operator
- Montana State AGbd_d1a549216a802d0f2023-09-15Verified by operator
- California State AGbd_967842f4b2ee04d22024-01-26 · +133dVerified
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Sep 15 (VT), last Jan 26 (CA) — a 133-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.