HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
1st Source Bank
bd_4a59c8811709f62b · schema v1 · pii pii-v1
Full breach record for 1st Source Bank →1st Source Bank disclosed a data breach involving the MOVEit software vulnerability exploited by an external actor. On June 1, 2023, the bank became aware of the vulnerability alert and patched its systems. Investigation revealed that data including names, Social Security numbers, driver's license numbers, and dates of birth may have been acquired without authorization. The bank engaged cybersecurity experts and offered 12 months of identity monitoring via Kroll.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_fda2be588d043776New Hampshire State AGfiled 2023-07-26Verified
- bd_08c27ccfede4e9efOregon State AGfiled 2023-07-27(1d gap)Verified
- bd_d0cebba25691bccfWashington State AGfiled 2023-07-20(6d gap)Verified
- bd_db8e5883d0d70d12Oregon State AGfiled 2023-07-20(6d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 16d gap
- bd_504a71c703e7184fCalifornia State AGfiled 2023-07-19(7d gap)Verified
- bd_644846888cf47c7fMontana State AGfiled 2023-07-19(7d gap)Verified
- bd_ee5f8afdf477969eMaine State AGfiled 2023-07-19(7d gap)Verified
- bd_a872f10fb82b1c59Vermont State AGfiled 2023-07-14(12d gap)Candidate
- bd_66ec9f2d6644e603SEC 8-Kfiled 2023-07-10(16d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570878
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 41e93426854b0a8b1e73d4daf02f3f0360e6728d009797c9fdf7bcb5d968bdc4
Reporting entity
- Name
- 1st Source Banknorm: 1st source bank
Victim entity
- Name
- 1st Source Banknorm: 1st source bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.