MalwareRansomwareCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Tri Counties Bank
bd_9d8a5b82fc79f500 · schema v1 · pii pii-v1
Full breach record for Tri Counties Bank →Tri Counties Bank experienced a malware incident on its internal network between February 7-8, 2023. The malware prevented access to certain files. An unauthorized actor may have accessed systems storing personal information, including names and potentially Social Security numbers, of customers, employees, and affiliates. The bank shut down systems, engaged third-party specialists, and notified law enforcement and regulators. Credit monitoring is being offered to affected individuals.
California clockDiscovered Feb 7, 2023 → Notified Nov 22, 2023288d ✗ CA 60-day late41 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3d1dd695dbfc9eb9New Hampshire State AGfiled 2023-11-22Verified
- bd_af220720d4d00291Vermont State AGfiled 2023-11-22Verified
- bd_201ae7fa1e3c8a63Maine State AGfiled 2023-10-12(41d gap)Candidate
- bd_3f1547cf3ba03ec1Montana State AGfiled 2023-10-12(41d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-576968
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- bd9d22596ef9c6be2f015dfd320f6030b733b1596a3dad1cc4ee4ec9207530e1
Reporting entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Victim entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- —
- Notification sent
- Nov 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- External
- Regulator citations
- Notified applicable regulatory authorities
Compliance
- Time to disclose
- 41 weeks(288 days from discovery to filing)
- Compliance flags
- CA 60-day late · 288d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 7, 2023→ Notified: Nov 22, 2023288d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.