MalwareRansomwareData EncryptedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Tri Counties Bank
bd_3d1dd695dbfc9eb9 · schema v1 · pii pii-v1
Full breach record for Tri Counties Bank →Tri Counties Bank notified New Hampshire residents on November 22, 2023, of a cybersecurity incident discovered on February 7, 2023. The bank's network was infected with malware, preventing access to files, between February 7 and 8, 2023. An unauthorized actor accessed systems storing personal information. The bank shut down systems, engaged forensic specialists, notified law enforcement, and provided credit monitoring and identity restoration services to 38 affected New Hampshire residents.
Leak gap clock✗ Leak >180d41 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 247 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_9d8a5b82fc79f500California State AGfiled 2023-11-22Verified
- bd_af220720d4d00291Vermont State AGfiled 2023-11-22Verified
- bd_201ae7fa1e3c8a63Maine State AGfiled 2023-10-12(41d gap)Candidate
- bd_3f1547cf3ba03ec1Montana State AGfiled 2023-10-12(41d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/tri-counties-bank-20231122.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- 5e9f185bb0df07a0fcf1cafdf0e24d52e5010c3fb8b5d714ee480895ea633c7e
Reporting entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Victim entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- —
- Notification sent
- Nov 22, 2023
- Affected individuals
- 38
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified applicable regulatory authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(288 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.