HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
1st Source Bank
bd_504a71c703e7184f · schema v1 · pii pii-v1
Full breach record for 1st Source Bank →1st Source Bank disclosed a data breach affecting customer information due to a vulnerability in the MOVEit file transfer software provided by Progress Software. The bank became aware of the vulnerability alert on June 1, 2023, and determined that data may have been acquired without authorization on June 24, 2023. Affected data includes names, Social Security numbers, driver's license numbers, and dates of birth. The bank patched the system, engaged cybersecurity experts, and offered 12 months of identity monitoring through Kroll.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_644846888cf47c7fMontana State AGfiled 2023-07-19Verified
- bd_ee5f8afdf477969eMaine State AGfiled 2023-07-19Verified
- bd_d0cebba25691bccfWashington State AGfiled 2023-07-20(1d gap)Verified
- bd_db8e5883d0d70d12Oregon State AGfiled 2023-07-20(1d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 9d gap
- bd_a872f10fb82b1c59Vermont State AGfiled 2023-07-14(5d gap)Candidate
- bd_4a59c8811709f62bCalifornia State AGfiled 2023-07-26(7d gap)Verified
- bd_fda2be588d043776New Hampshire State AGfiled 2023-07-26(7d gap)Verified
- bd_08c27ccfede4e9efOregon State AGfiled 2023-07-27(8d gap)Verified
- bd_66ec9f2d6644e603SEC 8-Kfiled 2023-07-10(9d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570547
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 19, 2023
- Raw hash
- c6dd5b5b390704b545d905eba185a32d17e7a570f1a8627d032c8013d824f5cf
Reporting entity
- Name
- 1st Source Banknorm: 1st source bank
Victim entity
- Name
- 1st Source Banknorm: 1st source bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(48 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.