MalwareRansomwareRansom DemandedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Great Plains State Bank
bd_764fa9a67a26e324 · schema v1 · pii pii-v1
Full breach record for Great Plains State Bank →Great Plains Bank Corporation reported a ransomware attack discovered on November 21, 2024, affecting its IT systems. The incident potentially exposed the names and Social Security numbers of 10 Maryland residents. The bank notified the FBI, engaged cybersecurity specialists, and is offering one year of complimentary credit monitoring through Experian to affected individuals.
Maryland clock⏱ MD AG >30d13 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
A leak claim by akira about this victim predates this filing by 65 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_7cc0083ed1c871afLeak Siteakirafiled 2024-12-16(65d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_52460b6e57da1cf6Indiana State AGfiled 2025-02-19Verified
- bd_a1f0277f73be677eVermont State AGfiled 2025-02-19Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376381.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 19, 2025
- Raw hash
- a919dc4bb51020b364630ad89f312326ed3a600743059cc3aef931814df4f6bb
Reporting entity
- Name
- Great Plains State Banknorm: great plains state bank
- Domain
- gpbankok.com
Victim entity
- Name
- Great Plains State Banknorm: great plains state bank
- Domain
- gpbankok.com
Incident
- Discovered
- Nov 21, 2024
- Materiality determined
- —
- Notification sent
- Feb 19, 2025
- Affected individuals
- 10
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified U.S. federal law enforcementNotified the Federal Bureau of Investigation (“FBI”)
Compliance
- Time to disclose
- 13 weeks(90 days from discovery to filing)
- Compliance flags
- MD AG >30dLeak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.