FEDERALHackingFinancial ServicesFinanceVulnerability ExploitZero-DaySupply Chain (3P Vendor)Low
Ameriserv Financial Bank
bd_418a81e6e86f2f8c · schema v1 · pii pii-v1
Full breach record for Ameriserv Financial Bank →AmeriServ Financial's 10-K Item 1C cybersecurity disclosure states the Company has not detected any material cybersecurity incident to its own systems. However, in Q2 2023, a prominent third-party vendor experienced a cybersecurity incident due to a previously unknown (zero-day) vulnerability in MOVEit Transfer file-sharing software. Further details referenced in the Company's Q2 and Q3 2023 Form 10-Q filings.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/707605/000155837024004100/asrv-20231231x10k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Mar 27, 2024
- Raw hash
- 37469f4b1c797c75c0ad955749f608fea4708016cc2632eaed539833a31c8c54
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Ameriserv Financial Banknorm: ameriserv financial bank
Victim entity
- Name
- Ameriserv Financial Banknorm: ameriserv financial bank
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.