DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitZero-DaySupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)PHIHealth (basic)LowContained

Cadence Bank

bd_967842f4b2ee04d2 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 1, 2023

Filed

Jan 26, 2024

To disclose

34 weeks

Affected

Not disclosed

Linked

7 filings

Confidence

66%
Full breach record for Cadence Bank3 incidents on file

Cadence Bank disclosed a data breach affecting current and former employees of Hall's Culligan, whose insurance was handled by Cadence Insurance (a Cadence Bank subsidiary). An unauthorized third party exploited a zero-day vulnerability in the MOVEit Transfer application (owned by Progress Software) to access and download data between May 28-31, 2023. Cadence Bank learned of the vulnerability on June 1, 2023. Affected data may include names, addresses, dates of birth, medical/treatment information, and health insurance information. Cadence Bank engaged forensic investigators, notified law enforcement, and implemented security enhancements.

California clockDiscovered Jun 1, 2023Notified Jan 26, 2024239d CA 60-day late34 weeks discovery → filing

Incident timeline

undetected · 4 days
discovery → filing · 34 weeks / 239 days

May 28, 2023

Begins

Jun 1, 2023

Discovered

Jan 26, 2024

Filed

vs. sector median

+25 wks slower

This filing is one of 7 about the same incident.View merged incident
A leak claim by cl0p about this victim predates this filing by 204 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (4) · sorted by filing gap

Filing propagation · 5 filings · 4 states

View merged incident ↗
California State AGSep 15 · first
Vermont State AGSep 15 · first
Massachusetts State AGSep 15 · first
Montana State AGSep 15 · first
California State AG+133d · this page

Pattern: first filing Sep 15 (CA), last Jan 26 (CA) — a 133-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.