DisclosureLens
MisuseFinancial ServicesFinancePrivilege AbuseEmployee Data InvolvedTargetedIdentity (basic)Government IDFinancial accountEmploymentMediumContained

CREDIT SUISSE AG

bd_43a4b495080aa7f6 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 14, 2023

Filed

Feb 14, 2023

To disclose

≤1 day

Affected

Not disclosed

Linked

4 filings

Confidence

69%
Full breach record for CREDIT SUISSE AG2 incidents on file

Credit Suisse Group AG notified Vermont AG of an insider threat incident where a former employee with legitimate access copied personal data (employment, SSN, bank account) to a personal device. No evidence of misuse found. Credit Suisse offered 12 months of Experian identity monitoring.

Vermont clock VT AG ≤14 bday≤1 day discovery → filing
notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.

Incident timeline

discovery → filing · ≤1 day / 0 days

Feb 14, 2023

Discovered

Feb 14, 2023

Filed

vs. sector median

9 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
Massachusetts State AGFeb 13 · first
Indiana State AGFeb 13 · first
Vermont State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.