HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
PlainsCapital Bank
bd_6a16364945d087db · schema v1 · pii pii-v1
Full breach record for PlainsCapital Bank →PlainsCapital Bank notified customers that a third-party vendor using MOVEit file transfer software was impacted by a global zero-day cyberattack between May 27 and May 31, 2023. The bank discovered the exposure on June 27, 2023. Customer data, including names, addresses, and potentially Social Security numbers and financial account information, was likely obtained by an unauthorized party. The bank is offering 12 months of credit monitoring and identity restoration services.
California clockDiscovered Jun 27, 2023 → Notified Jul 14, 202317d ✓ CA 60-day OK17 days discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_d0fa7306adbe4d64Montana State AGfiled 2023-07-14Verified
- bd_651ddcbce2bbcb28SEC 8-Kfiled 2023-07-03(11d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-570311
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2023
- Raw hash
- d4b57a8a4d1681f70d5a5553cd80ff1fd478d20be1a385feb02077ab11df095c
Reporting entity
- Name
- PlainsCapital Banknorm: plainscapital bank
Victim entity
- Name
- PlainsCapital Banknorm: plainscapital bank
Incident
- Discovered
- Jun 27, 2023
- Materiality determined
- —
- Notification sent
- Jul 14, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- External
- Third party
- via MOVEit vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 17 days(17 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 17d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 27, 2023→ Notified: Jul 14, 202317d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.