DisclosureLens
HackingFinancial ServicesFinanceCustomer Data InvolvedSupply Chain (3P Vendor)Identity (basic)Financial accountFinancial credentialsMediumContained

Community Trust Bank, Inc.

bd_3f94dfb292e98775 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Aug 9, 2023

Filed

Sep 8, 2023

To disclose

4 weeks

Affected · nationwide

99,3892 in this filing

Linked

3 filings

Confidence

50%
Full breach record for Community Trust Bank, Inc.

Community Trust Bank reported a data breach caused by an external hacking incident that occurred on May 27, 2023. The breach was discovered on August 9, 2023, and affected 2 Maine residents. The compromised information includes names and financial account numbers with associated access codes or PINs. The notification was submitted by outside counsel for Fidelity National Information Services, Inc., indicating a third-party vendor was involved in the incident. Affected individuals were notified on September 8, 2023, and offered 24 months of identity theft protection services.

Maine clockDiscovered Aug 9, 2023Filed with AG Sep 8, 202330d ME AG ≤30d4 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 74 days
discovery → filing · 4 weeks / 30 days

May 27, 2023

Begins

Aug 9, 2023

Discovered

Sep 8, 2023

Filed

vs. sector median

4 wks faster

This filing is one of 3 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Indiana State AGSep 8 · first
Maine State AGSep 8 · first · this page

Pattern: first filing Sep 8 (IN), last Sep 15 (NH) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.