The Bank of Canton
bd_4442f0b0462eac94 · schema v1 · pii pii-v1
Full breach record for The Bank of Canton →Bank of Canton notified the New Hampshire Attorney General of a data security incident involving its third-party service provider's use of Progress Software's MOVEit application. The provider suffered a cybersecurity incident on or around May 27, 2023, exploiting a previously unknown vulnerability. Bank of Canton was notified on August 3, 2023. Approximately 41 New Hampshire residents were affected. Personal information related to deposit accounts was potentially obtained. No evidence of misuse was found. Notifications were mailed on October 20, 2023, offering credit monitoring.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_7f4530eae54bd202Maine State AGfiled 2023-10-23Candidate
- bd_456ec0a1d3fd0519Vermont State AGfiled 2023-10-20(3d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bank-canton-20231023.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 23, 2023
- Raw hash
- 1ef736c5285eb3eafb9a23f380a30eb5290616fe3aa93076c5bcf858d1e2890f
Reporting entity
- Name
- GOODWIN PROCTER LLPnorm: goodwin procter
- Domain
- goodwinlaw.com
Victim entity
- Name
- The Bank of Cantonnorm: the bank of canton
- Industry
- financial_services
Incident
- Discovered
- Aug 3, 2023
- Materiality determined
- —
- Notification sent
- Oct 20, 2023
- Affected individuals
- 41
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Department of Justice Office of the Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.