HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Northfield Bank
bd_9963040c41fa4926 · schema v1 · pii pii-v1
Full breach record for Northfield Bank →Northfield Bank notified New Hampshire residents of a data security event involving a third-party vendor's use of MOVEit Transfer software. The incident occurred between May 27 and May 31, 2023, and the bank was notified on August 4, 2023. The breach potentially exposed customer personal information, including government identifiers, via vulnerabilities in the vendor's file transfer application. Northfield Bank engaged cybersecurity specialists and provided credit monitoring services through Kroll to affected individuals.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_e04b124b7a8d579eVermont State AGfiled 2023-09-08Candidate
- bd_79fd0089944d1124Maine State AGfiled 2023-09-07(1d gap)Candidate
- bd_d86ff387ddb8a86aVermont State AGfiled 2023-09-25(17d gap)Verified
- bd_d9885b4724d48106New Hampshire State AGfiled 2023-10-02(24d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/northfield-bank-20230908.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 8, 2023
- Raw hash
- 8db4ab7b26d9901d8d1189ba64906647c044bb9716abb70bb7ee48f560455107
Reporting entity
- Name
- Northfield Banknorm: northfield bank
Victim entity
- Name
- Northfield Banknorm: northfield bank
Incident
- Discovered
- Aug 4, 2023
- Materiality determined
- —
- Notification sent
- Sep 7, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- Partner
- Regulator citations
- providing notice of this incident to relevant state and federal regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.