Cadence Bank
bd_967842f4b2ee04d2 · schema v1 · pii pii-v1
Full breach record for Cadence Bank →3 incidents on fileCadence Bank disclosed a data breach affecting current and former employees of Hall's Culligan, whose insurance was handled by Cadence Insurance (a Cadence Bank subsidiary). An unauthorized third party exploited a zero-day vulnerability in the MOVEit Transfer application (owned by Progress Software) to access and download data between May 28-31, 2023. Cadence Bank learned of the vulnerability on June 1, 2023. Affected data may include names, addresses, dates of birth, medical/treatment information, and health insurance information. Cadence Bank engaged forensic investigators, notified law enforcement, and implemented security enhancements.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
Jun 1, 2023
Discovered
Jan 26, 2024
Filed
vs. sector median
+25 wks slower
Linked disclosures
Why this link?Ransomware claims (2)
- Leak Sitedispossessorbd_955b68cfd2f4b2942024-04-19 · +84dVerified by operator
- Leak Sitecl0pbd_904e886fa624bb042023-07-06 · +204dVerified by operator
Regulatory filings (4) · sorted by filing gap
- California State AGbd_3a402a6f99ec3ecc2023-09-15 · +133dVerified by operator
- Vermont State AGbd_9eeb910d8c5188af2023-09-15 · +133dVerified by operator
- Massachusetts State AGbd_b9c2b0baae525a492023-09-15 · +133dVerified by operator
- Montana State AGbd_d1a549216a802d0f2023-09-15 · +133dVerified by operator
Filing propagation · 5 filings · 4 states
View merged incident ↗Pattern: first filing Sep 15 (CA), last Jan 26 (CA) — a 133-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.