FIRST MERCHANTS CORP
bd_6e667230854a713c · schema v1 · pii pii-v1
Full breach record for FIRST MERCHANTS CORP →A bank holding company disclosed in its 2023 10-K Item 1C that customer data was potentially included in the global MOVEit Transfer (Progress Software) incident. The compromise affected a third-party financial-institution vendor, not the Bank's own network. Online/mobile banking customers' personal information may have been copied. The vendor applied Progress's recommended patches; the Bank notified affected customers. Cyber insurance is expected to cover many related costs. Described as the only cybersecurity incident that materially affected the Corporation in FY2023.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2023
Begins
Feb 29, 2024
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.