HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedN-DayPIIIDENTITY_BASICLowContained
Sunflower Bank, National Association
bd_895de35e1cea98f0 · schema v1 · pii pii-v1
Full breach record for Sunflower Bank, National Association →Sunflower Bank, N.A. was notified on or about May 31, 2023 by Progress Software Corporation of a vulnerability in MOVEit file transfer software, which the bank used for secure file transfers. The bank's MOVEit server was segmented from core systems. Potentially impacted data included names, and financial transaction-related information. The bank engaged outside experts, applied all available fixes, and offered affected individuals Experian credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_ef42af6291b75a20New Hampshire State AGfiled 2023-08-15Verified
- bd_d36ee2ad177829e8SEC 8-Kfiled 2023-07-14(32d gap)Verified
- bd_46ae3c2793a32792New Hampshire State AGfiled 2023-10-02(48d gap)Verified
- bd_fea17e438a10a5c6California State AGfiled 2023-10-04(50d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571902
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2023
- Raw hash
- 78ced8fe1efc2076632fde00ffcaecb3e0755a32f2d81229aaa57cfd855c4ba6
Reporting entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
Victim entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Aug 14, 2023
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reported incident to law enforcement
- Third party
- via Progress Software Corporation
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.