Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedPIICREDENTIALSLowContained
Byline Bank
bd_54f0b4d25f9a9bd0 · schema v1 · pii pii-v1
Full breach record for Byline Bank →Byline Bank notified customers of a security incident where unauthorized access to an employee's email account, likely via phishing, led to the compromise of certain customer information. The bank secured accounts, investigated, and offered 12 months of credit monitoring.
Vermont clock⏱ VT AG >14 bday4 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2024-05-23-byline-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2024
- Raw hash
- 0b63aa5ba5d2dd869c05c37ae48208271a2ef79e1ef863925bb7fb643e003381
Reporting entity
- Name
- Byline Banknorm: byline bank
Victim entity
- Name
- Byline Banknorm: byline bank
Incident
- Discovered
- Apr 22, 2024
- Materiality determined
- —
- Notification sent
- May 23, 2024
- Affected individuals
- Not disclosed
- Data types
- PIICREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.