HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Union Bank and Trust Company
bd_6001904e35e21205 · schema v1 · pii pii-v1
Full breach record for Union Bank and Trust Company →Union Bank and Trust Company notified consumers of a data breach involving the MOVEit Transfer software provided by Progress Software. A zero-day vulnerability was exploited on May 29, 2023, leading to unauthorized access to customer names and government-issued ID data. UBT took the application offline, engaged forensic specialists, notified federal law enforcement, and applied a security patch. Free identity monitoring was offered to affected individuals.
Vermont clock⏱ VT AG >14 bday29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_4f3dcdbe7d2893dbMontana State AGfiled 2023-06-30(1d gap)Candidate
- bd_8ab6f751d660d5deMaine State AGfiled 2023-06-30(1d gap)Candidate
- bd_905a3e576ec7a71fCalifornia State AGfiled 2023-06-30(1d gap)Verified
- bd_4f0513010f0b4733New Hampshire State AGfiled 2023-07-05(6d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-06-29-union-bank-and-trust-company-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 29, 2023
- Raw hash
- bc0674a08279d4eb2e9632abe3f4cf11688549fad0a904e3607b6bfd5633a1ad
Reporting entity
- Name
- Union Bank and Trust Companynorm: union bank and
Victim entity
- Name
- Union Bank and Trust Companynorm: union bank and
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Jun 29, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the event to federal law enforcement
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.