FEDERALItem 8.01 · voluntaryHackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumActive
Umpqua Bank
bd_4d92681387db7779 · schema v1 · pii pii-v1
Full breach record for Umpqua Bank →Umpqua Bank, a subsidiary of Columbia Banking System, disclosed a third-party vendor incident involving MOVEit file-sharing software. The vendor reported unauthorized access to consumer and small business customer names and SSNs/TINs. Umpqua notified affected customers via email on June 22, 2023, and engaged forensic investigators. No commercial customer data was compromised.
SEC clockMateriality determined Jun 27, 2023 → Filed Jun 27, 20230d ✓ SEC 4-day OK6 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d3b7a25fe28a7b9bCalifornia State AGfiled 2023-08-11(45d gap)Verified
- bd_d739cdfb0d8e16a8Maine State AGfiled 2023-08-11(45d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/887343/000088734323000274/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 27, 2023
- Raw hash
- b8a06db58ad202bcbc7b9f80cc0a80e429cae03ca2f5e87b7f429ee154d98f68
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Columbia Banking System, Inc.norm: columbia banking system
- SEC CIK
- 0000887343
Victim entity
- Name
- Umpqua Banknorm: umpqua bank
Incident
- Discovered
- Jun 21, 2023
- Materiality determined
- Jun 27, 2023
- Notification sent
- Jun 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 days(6 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 27, 2023→ Filed: Jun 27, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.