HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Sunflower Bank, National Association
bd_46ae3c2793a32792 · schema v1 · pii pii-v1
Full breach record for Sunflower Bank, National Association →Sunflower Bank, N.A. filed a supplemental data security incident notice with the New Hampshire Attorney General regarding a MOVEit zero-day vulnerability exploit. The bank notified 23 New Hampshire residents starting August 14, 2023. The incident involved unauthorized access via a third-party software vulnerability, resulting in the exfiltration of customer data. The bank is offering credit monitoring services to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_fea17e438a10a5c6California State AGfiled 2023-10-04(2d gap)Verified
- bd_895de35e1cea98f0California State AGfiled 2023-08-15(48d gap)Verified
- bd_ef42af6291b75a20New Hampshire State AGfiled 2023-08-15(48d gap)Verified
- bd_d36ee2ad177829e8SEC 8-Kfiled 2023-07-14(80d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sunflower-bank-20231002.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 2, 2023
- Raw hash
- 82875acebe46f1a5a8ec220b7980e93d9fb053ff3830be0932a8244230b370db
Reporting entity
- Name
- Nelson Mullins Riley & Scarborough LLPnorm: nelson mullins riley scarborough
Victim entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
- Industry
- financial_services
Incident
- Discovered
- Aug 14, 2023
- Materiality determined
- —
- Notification sent
- Aug 15, 2023
- Affected individuals
- 23
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.