DisclosureLens
MalwareFinancial ServicesFinanceRansomwareCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDMediumContained

Tri Counties Bank

bd_9d8a5b82fc79f500 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 7, 2023

Filed

Nov 22, 2023

To disclose

41 weeks

Affected

Not disclosed

Linked

11 filings

Confidence

65%
Full breach record for Tri Counties Bank

Tri Counties Bank experienced a malware incident on its internal network between February 7-8, 2023. The malware prevented access to certain files. An unauthorized actor may have accessed systems storing personal information, including names and potentially Social Security numbers, of customers, employees, and affiliates. The bank shut down systems, engaged third-party specialists, and notified law enforcement and regulators. Credit monitoring is being offered to affected individuals.

California clockDiscovered Feb 7, 2023Notified Nov 22, 2023288d CA 60-day late41 weeks discovery → filing

Incident timeline

discovery → filing · 41 weeks / 288 days

Feb 7, 2023

Begins

Feb 7, 2023

Discovered

Nov 22, 2023

Filed

vs. sector median

+33 wks slower

This filing is one of 11 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 247 days.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (9) · sorted by filing gap

Show 5 more filingsup to 41d gap

Filing propagation · 10 filings · 7 states

View merged incident ↗
Maine State AGOct 12 · first
Montana State AGOct 12 · first
Indiana State AGOct 12 · first
Massachusetts State AGOct 12 · first
California State AGOct 12 · first
California State AG+41d · this page

Pattern: first filing Oct 12 (ME), last Nov 22 (CA) — a 41-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.