HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Varo Bank, National Association
bd_70cc782e61e6813b · schema v1 · pii pii-v1
Full breach record for Varo Bank, National Association →Varo Bank, N.A. reported a data breach affecting 7,007 individuals, which occurred on March 12, 2024, and was discovered on April 10, 2024. The breach was an external system hack that exposed names and financial account or payment card numbers along with their associated security codes, access codes, passwords, or PINs. The bank notified affected individuals electronically on May 7, 2024, and offered credit monitoring and identity restoration services.
Maine clockDiscovered Apr 10, 2024 → Filed with AG May 7, 202427d ✓ ME AG ≤30d27 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_036b60ed2a159b94Vermont State AGfiled 2024-05-07Verified
- bd_11e27d56c7b6753dMontana State AGfiled 2024-05-07Candidate
- bd_8777007060b756caCalifornia State AGfiled 2024-05-07Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/ff99ce4b-7e31-4485-9a6a-e03a50758987.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 7, 2024
- Raw hash
- 746a1651ee3359ce59164916c1f51caf617afbbf40dbd2600df7c9f49c2e35b2
Reporting entity
- Name
- Varo Bank, National Associationnorm: varo bank national
Victim entity
- Name
- Varo Bank, National Associationnorm: varo bank national
Incident
- Discovered
- Apr 10, 2024
- Materiality determined
- —
- Notification sent
- May 7, 2024
- Affected individuals
- 7,007
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 27d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 10, 2024→ Filed with AG: May 7, 202427d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.