DisclosureLens
MalwareFinancial ServicesFinanceRansomwareStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

Carson Bank

bd_4c26bef928b783e8 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 22, 2020

Filed

Dec 29, 2020

To disclose

10 weeks

Affected

1state residents only

Linked

5 filings

Confidence

67%
Full breach record for Carson Bank

Carson Bank notified the NH Attorney General that its third-party software provider, American Bank Systems (ABS), suffered a cybercrime attack involving malware on October 22, 2020. ABS discovered the incident on that date and notified Carson Bank on November 18, 2020. The attack resulted in the access or acquisition of customer files containing names, addresses, bank account numbers, and Social Security numbers. One New Hampshire resident was affected. Carson Bank is offering 12 months of credit monitoring. ABS implemented remediation measures including password resets and advanced endpoint monitoring.

Incident timeline

discovery → filing · 10 weeks / 68 days

Oct 22, 2020

Discovered

Dec 29, 2020

Filed

vs. sector median

on median

This filing is one of 5 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 5 states

View merged incident ↗
Montana State AGDec 28 · first
Maine State AGDec 28 · first
Indiana State AGDec 28 · first
New Hampshire State AG+1d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.