HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Important News from Rockland Trust and Enterprise Bank
bd_4920e1793ad68492 · schema v1 · pii pii-v1
Full breach record for Important News from Rockland Trust and Enterprise Bank →Enterprise Bank & Trust Company notified New Hampshire residents of a data breach involving the MOVEit Transfer vulnerability. An unknown actor exploited the vulnerability on May 27, 2023, accessing the server and exfiltrating names, SSNs, and financial account information. Approximately 251 NH residents were notified on September 7, 2023. The bank provided credit monitoring via Experian and notified state regulators.
Leak gap clock⏱ Leak >30d15 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed251 affectedView incident
A leak claim by cl0p about this victim predates this filing by 43 days.View originating leak claim
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/enterprise-bank-trust-company-20230907.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 7, 2023
- Raw hash
- c71ddc71c2f73c9b43113cb5585eed35674201d9231c89e85f4ac81c31d595b7
Reporting entity
- Name
- Important News from Rockland Trust and Enterprise Banknorm: important news from rockland trust and enterprise bank
- Domain
- enterprisebanking.com
Victim entity
- Name
- Important News from Rockland Trust and Enterprise Banknorm: important news from rockland trust and enterprise bank
- Domain
- enterprisebanking.com
Incident
- Discovered
- May 27, 2023
- Materiality determined
- —
- Notification sent
- Sep 7, 2023
- Affected individuals
- 251
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- providing written notice of this incident to relevant state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 15 weeks(103 days from discovery to filing)
- Compliance flags
- Leak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.