HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Cadence Bank
bd_972d0b95bc92e6fa · schema v1 · pii pii-v1
Full breach record for Cadence Bank →Cadence Bank notified customers of a data security incident involving a previously unknown vulnerability in the ACH Transfer application owned by Progress Software Corporation. An unauthorized third party exploited this zero-day vulnerability between May 28 and May 31, 2023, accessing and downloading personal information. The bank launched a forensic investigation, contacted law enforcement, and offered identity protection services. Affected data may include name, address, date of birth, SSN, driver's license, passport number, and financial account information.
California clockDiscovered Jun 1, 2023 → Notified Nov 22, 2023174d ✗ CA 60-day late25 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_29237302c92f6eefVermont State AGfiled 2023-11-22Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576943
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- 23363538c8d775140783541d7584250e7d08ab9ace65c536f17b09e80d3d7d2b
Reporting entity
- Name
- Cadence Banknorm: cadence bank
Victim entity
- Name
- Cadence Banknorm: cadence bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Nov 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 25 weeks(174 days from discovery to filing)
- Compliance flags
- CA 60-day late · 174d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2023→ Notified: Nov 22, 2023174d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.