DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitData ExfiltratedCustomer Data InvolvedTargetedGovernment IDIdentity (basic)Financial accountMediumContained

Continental Bancorporation

bd_46c2d0f0a329cfc6 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Apr 10, 2025

Filed

Aug 8, 2025

To disclose

17 weeks

Affected

1state residents only

Linked

3 filings

Confidence

66%
Full breach record for Continental Bancorporation

Continental Bancorporation notified the NH Attorney General of a cybersecurity incident involving one New Hampshire resident. An unauthorized party exploited a vulnerability in CrushFTP server software to access the internal network. Personal information (name, SSN, account number, DOB) of one resident was accessed between March 31 and April 10, 2025. Continental contained the network, engaged forensic investigators, and offered credit monitoring.

Incident timeline

undetected · 10 days
discovery → filing · 17 weeks / 120 days

Mar 31, 2025

Begins

Apr 10, 2025

Discovered

Aug 8, 2025

Filed

vs. sector median

+9 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Indiana State AGAug 4 · first
New Hampshire State AG+4d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.