FIRST MERCHANTS CORP
bd_6e667230854a713c · schema v1 · pii pii-v1
Full breach record for FIRST MERCHANTS CORP →A bank holding company disclosed in its 2023 10-K Item 1C that customer data was potentially included in the global MOVEit Transfer (Progress Software) incident. The compromise affected a third-party financial-institution vendor, not the Bank's own network. Online/mobile banking customers' personal information may have been copied. The vendor applied Progress's recommended patches; the Bank notified affected customers. Cyber insurance is expected to cover many related costs. Described as the only cybersecurity incident that materially affected the Corporation in FY2023.
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/712534/000071253424000071/frme-20231231.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 29, 2024
- Raw hash
- dc975d4887128ac5c9d1d44a1eed5e2123db34fa287ddd6594bac392bf4b72d9
Source filing
Reporting entity
- Name
- FIRST MERCHANTS CORPnorm: first merchants
- SEC CIK
- 712534
Victim entity
- Name
- FIRST MERCHANTS CORPnorm: first merchants
- SEC CIK
- 712534
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.