DisclosureLens
FEDERALHackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Supply Chain (Dependency)Customer Data InvolvedDownstream VictimsN-DayPIIIdentity (basic)LowResolved

FIRST MERCHANTS CORP

bd_6e667230854a713c · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Feb 29, 2024

To disclose

Affected

Not disclosed

Confidence

66%
Full breach record for FIRST MERCHANTS CORP

A bank holding company disclosed in its 2023 10-K Item 1C that customer data was potentially included in the global MOVEit Transfer (Progress Software) incident. The compromise affected a third-party financial-institution vendor, not the Bank's own network. Online/mobile banking customers' personal information may have been copied. The vendor applied Progress's recommended patches; the Bank notified affected customers. Cyber insurance is expected to cover many related costs. Described as the only cybersecurity incident that materially affected the Corporation in FY2023.

Incident timeline

Jan 1, 2023

Begins

Feb 29, 2024

Filed

Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.No incident reportedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.