DisclosureLens
AccidentalFinancial ServicesFinanceMisdeliverySupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDFinancial accountFinancialMediumResolved

Centennial Bank, including its division Happy State Bank

bd_9cb4046dd9113585 · schema v1 · pii pii-v2

Severity

Medium

Discovered

Aug 17, 2026

Filed

Sep 1, 2026

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

69%
Full breach record for Centennial Bank, including its division Happy State Bank

Centennial Bank notified Massachusetts residents that a third-party service provider, Fidelity Information Services (FIS), inadvertently sent a file containing customer personal information (including names, addresses, dates of birth, account numbers, and Social Security numbers) to an unintended recipient at another financial institution on August 7, 2026. The Bank was notified by FIS on August 17, 2026. The unintended recipient confirmed deletion of the file. The Bank and FIS took immediate steps to contain the incident, including recalling the email and terminating access. FIS retrained the associate and implemented enhanced validation procedures. The Bank offered 24 months of complimentary identity monitoring services.

Incident timeline

undetected · 10 days

Aug 7, 2026

Begins

Aug 17, 2026

Discovered

Sep 1, 2026

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGSep 1 · first · this page

Pattern: first filing Sep 1 (MA), last Sep 17 (TX) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.