FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASICMediumActive
Pacific Premier Bank, National Association
bd_5299e68a7eef511d · schema v1 · pii pii-v1
Full breach record for Pacific Premier Bank, National Association →Pacific Premier Bancorp reported a third-party vendor incident on July 20, 2023, involving the MOVEit Transfer zero-day vulnerability. Pacific Premier Bank's vendor was compromised, exposing client data including SSNs, account numbers, and PII. The vendor patched the vulnerability. The Bank is investigating scope and notifying regulators/clients. No impact to Bank's internal network.
SEC clockMateriality determined Jul 25, 2023 → Filed Jul 25, 20230d ✓ SEC 4-day OK5 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1028918/000102891823000106/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 25, 2023
- Raw hash
- 4337b5db14a266ddf878fda7396d32b88642e4d88d20152ecb3377b37be2abc2
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- PACIFIC PREMIER BANCORP, INC.norm: pacific premier bancorp
- SEC CIK
- 0001028918
Victim entity
- Name
- Pacific Premier Bank, National Associationnorm: pacific premier bank national
Incident
- Discovered
- Jul 20, 2023
- Materiality determined
- Jul 25, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- The Bank is working with Vendor to provide appropriate notifications to potentially affected parties and to regulatory agencies as required by federal and state law
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jul 25, 2023→ Filed: Jul 25, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.