HackingSupply Chain (3P Vendor)Data ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
KeyBank National Association
bd_a4f654df6f257b9b · schema v1 · pii pii-v1
Full breach record for KeyBank National Association →KeyBank disclosed a data breach involving its vendor, Overby-Seawell Company (OSC). An unauthorized external party gained remote access to OSC's network on July 5, 2022, and exfiltrated mortgage client data. Affected data includes names, mortgage property addresses, account numbers, and home insurance policy numbers. No Social Security Numbers were compromised. KeyBank notified affected clients and offered two years of Equifax credit monitoring. The FBI was notified.
California clockDiscovered Aug 4, 2022 → Notified Aug 4, 20220d ✓ CA 60-day OK11 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_204b30c931f55115Oregon State AGfiled 2022-10-21Verified
- bd_6ac2e700788c603bOregon State AGfiled 2022-08-30(52d gap)Verified
- bd_770a2169c5d0839cWashington State AGfiled 2022-08-26(56d gap)Candidate
- bd_b28da354340c3c8cCalifornia State AGfiled 2022-08-26(56d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 56d gap
- bd_f081eecb38503eeeMontana State AGfiled 2022-08-26(56d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-558511
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 21, 2022
- Raw hash
- 3d6b9f9ea438c0bc96be52a29d38d2a639f6a04bacc473f9da63eb3807978d21
Reporting entity
- Name
- KeyBank National Associationnorm: keybank national
Victim entity
- Name
- KeyBank National Associationnorm: keybank national
Incident
- Discovered
- Aug 4, 2022
- Materiality determined
- —
- Notification sent
- Aug 4, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Overby-Seawell Company
- Initial access
- supply_chain
Compliance
- Time to disclose
- 11 weeks(78 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 4, 2022→ Notified: Aug 4, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.