FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
1st Source Bank
bd_66ec9f2d6644e603 · schema v1 · pii pii-v1
Full breach record for 1st Source Bank →1st Source Bank, a subsidiary of 1st Source Corp, disclosed a cybersecurity incident stemming from a vulnerability in Progress Software's MOVEit file transfer software. An unauthorized third party gained access to sensitive client data, including PII. The company patched the software, engaged forensic experts, and is notifying affected clients, offering credit monitoring. The investigation is ongoing.
SEC clockMateriality determined Jul 10, 2023 → Filed Jul 10, 20230d ✓ SEC 4-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_a872f10fb82b1c59Vermont State AGfiled 2023-07-14(4d gap)Candidate
- bd_504a71c703e7184fCalifornia State AGfiled 2023-07-19(9d gap)Verified
- bd_644846888cf47c7fMontana State AGfiled 2023-07-19(9d gap)Verified
- bd_ee5f8afdf477969eMaine State AGfiled 2023-07-19(9d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 17d gap
- bd_d0cebba25691bccfWashington State AGfiled 2023-07-20(10d gap)Verified
- bd_db8e5883d0d70d12Oregon State AGfiled 2023-07-20(10d gap)Verified
- bd_4a59c8811709f62bCalifornia State AGfiled 2023-07-26(16d gap)Verified
- bd_fda2be588d043776New Hampshire State AGfiled 2023-07-26(16d gap)Verified
- bd_08c27ccfede4e9efOregon State AGfiled 2023-07-27(17d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/34782/000003478223000104/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 10, 2023
- Raw hash
- 3f0909daa3d346aa28dda2b3d611c1b34be545533f72dc95a31046f7fcaf1597
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- 1ST SOURCE CORPnorm: 1st source
- SEC CIK
- 0000034782
- Domain
- 1stsource.com
Victim entity
- Name
- 1st Source Banknorm: 1st source bank
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jul 10, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- in contact with law enforcement and regulatory authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(40 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jul 10, 2023→ Filed: Jul 10, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.