Social EngineeringPhishingBECCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighResolved
Happy State Bank
bd_70e55aee5b5d69a9 · schema v1 · pii pii-v1
Full breach record for Happy State Bank →Happy State Bank reported a business email compromise incident occurring July 28-29, 2022. The breach affected 10,069 individuals, including 1 Maine resident. Compromised data included names and Social Security Numbers. Notification was sent on March 16, 2023, with 12 months of credit monitoring offered.
Maine clockDiscovered Feb 7, 2023 → Filed with AG Mar 16, 202337d ⏱ ME AG >30d5 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_aa1b7f0ac3c73c49Montana State AGfiled 2023-03-16Candidate
- bd_935e22ed084dd01aMaine State AGfiled 2023-04-27(42d gap)Verified by operator
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/fe93a1a4-6d7c-4833-b110-bc795599b539.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 16, 2023
- Raw hash
- 065158e37fcecdc73edd5b1ff2f94f96ab17602af16d12d02c7f74651664888e
Reporting entity
- Name
- Happy State Banknorm: happy state bank
- Domain
- happybank.com
- Industry
- Financial Services
Victim entity
- Name
- Happy State Banknorm: happy state bank
- Domain
- happybank.com
- Industry
- Financial Services
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- —
- Notification sent
- Mar 16, 2023
- Affected individuals
- 10,069
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(37 days from discovery to filing)
- Compliance flags
- ME AG >30d · 37d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 7, 2023→ Filed with AG: Mar 16, 202337d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.