HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
GEMINI TRUST COMPANY, LLC
bd_3ce842f296c2e194 · schema v1 · pii pii-v1
Full breach record for GEMINI TRUST COMPANY, LLC →Gemini Trust Company, LLC notified customers that a third-party ACH banking partner experienced a security incident involving one of its service providers. An unauthorized actor gained access to an internal collaboration tool on the bank partner's system between June 3 and June 7, 2024, potentially exposing customer names, bank account numbers, and routing numbers. No other sensitive information (SSN, DOB, passwords) was impacted. The banking partner launched an investigation, contained the incident, engaged forensic experts, and notified law enforcement.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-589257
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 24, 2024
- Raw hash
- 347974fce05916f726ed7224f2aa23609455667b9408bebbb880be3ea558e045
Reporting entity
- Name
- GEMINI TRUST COMPANY, LLCnorm: gemini trust
- Domain
- gemini.com
Victim entity
- Name
- GEMINI TRUST COMPANY, LLCnorm: gemini trust
- Domain
- gemini.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 25, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Third party
- via ACH banking partner
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.