HackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
Arvest Bank
bd_74c4d616e0098e3f · schema v1 · pii pii-v1
Full breach record for Arvest Bank →Arvest Bank reported a cybersecurity incident involving its third-party vendor, Fiserv. Between May 27 and May 31, 2023, a zero-day SQL injection vulnerability in Fiserv's MOVEit Transfer tool was exploited, resulting in the exfiltration of customer data. The breach was discovered on October 13, 2023. A total of 26,388 individuals were affected, including one Maine resident. Arvest Bank notified affected individuals on January 30, 2024, and provided two years of identity theft protection services.
Maine clockDiscovered Oct 13, 2023 → Filed with AG Feb 1, 2024111d ✗ ME AG >90d16 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed26,388 affectedView incident
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/a776e5c5-00ac-4dc7-8f95-e69b3478fda1.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 1, 2024
- Raw hash
- 118a7afc309f41fe4c2d8530ac742ff72c1ccaa03eaad0585aa826d730133362
Reporting entity
- Name
- Arvest Banknorm: arvest bank
- Domain
- arvest.com
- Industry
- Financial Services
Victim entity
- Name
- Arvest Banknorm: arvest bank
- Domain
- arvest.com
- Industry
- Financial Services
Incident
- Discovered
- Oct 13, 2023
- Materiality determined
- —
- Notification sent
- Jan 30, 2024
- Affected individuals
- 26,388
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 16 weeks(111 days from discovery to filing)
- Compliance flags
- ME AG >90d · 111dME resident >60d · 109d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Oct 13, 2023→ Filed with AG: Feb 1, 2024111d 90 days ME AG >90d Maine Discovered: Oct 13, 2023→ Notified: Jan 30, 2024109d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.