MisuseData MishandlingEmployee Data InvolvedCustomer Data InvolvedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Malaga Bank F.S.B.
bd_a31a3278aca71c72 · schema v1 · pii pii-v1
Full breach record for Malaga Bank F.S.B. →Meriplex Communications, Ltd., an IT service provider for Malaga Bank, reported that a former employee downloaded customer data including names and Social Security numbers. The incident occurred between November 17, 2021, and August 30, 2022, and was discovered on August 30, 2022. Meriplex terminated the employee, notified law enforcement, engaged forensic investigators, and implemented security controls. Affected individuals are offered 24 months of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-561473
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 9, 2023
- Raw hash
- fb06b8199163aa56afc46001099273c51f50845ddc4bc44a7c66da7d15ac7b28
Reporting entity
- Name
- Meriplex Communications, Ltd.norm: meriplex communications
Victim entity
- Name
- Malaga Bank F.S.B.norm: malaga bank fsb
Incident
- Discovered
- Aug 30, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Internal
- Regulator citations
- Notified state and federal law enforcement
- Third party
- via Meriplex Communications, Ltd.
- Initial access
- insider_action
Compliance
- Time to disclose
- 19 weeks(132 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.