FEDERALItem 8.01 · voluntaryHackingFinancial ServicesFinanceVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedDownstream VictimsPIIIDENTITY_BASICMediumActive
Sound Community Bank
bd_58f08c8f117da1a8 · schema v1 · pii pii-v1
Full breach record for Sound Community Bank →Sound Financial Bancorp disclosed that its subsidiary Sound Community Bank was affected by the MOVEit Transfer zero-day vulnerability (Progress Software) via a third-party vendor providing account hosting and transaction processing. The vendor used MOVEit to transfer data on approximately 16,000 of the Bank's mobile and online banking customers. Vendor forensics indicate the data was downloaded once during a valid transfer; investigation ongoing. Law enforcement and banking regulators notified.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_cf9ca7f029a63bdaMaine State AGfiled 2023-07-17(3d gap)Candidate
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1541119/000092708923000102/sfbc20230713_8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 14, 2023
- Raw hash
- 0f6ce9d2f2d483cde732b9cffe901d5e1f5f505deb852ac2732e990faf685194
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Sound Financial Bancorp, Inc.norm: sound financial bancorp
- SEC CIK
- 0001541119
Victim entity
- Name
- Sound Community Banknorm: sound community bank
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 16,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1567 Exfiltration Over Web Service
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified primary banking regulators
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.