HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Enterprise Bank and Trust Company
bd_a5756f65ca3456db · schema v1 · pii pii-v1
Full breach record for Enterprise Bank and Trust Company →Enterprise Bank & Trust Company notified consumers of a data breach involving its MOVEit Transfer server, exploited by an unknown actor via a vulnerability in Progress Software Corp.'s third-party file transfer tool. The incident resulted in the exfiltration of customer names and financial account information. The bank applied patches, investigated, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday10 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_b19276c8873bf3eaMaine State AGfiled 2023-09-07(31d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-07-enterprise-bank-trust-company-progres-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 7, 2023
- Raw hash
- 3db9b8ca9ef59d911224e79da794e4ff13194b56d1819c21750e2bd4fb345fd6
Reporting entity
- Name
- Enterprise Bank and Trust Companynorm: enterprise bank and
- Domain
- enterprisebanking.com
Victim entity
- Name
- Enterprise Bank and Trust Companynorm: enterprise bank and
- Domain
- enterprisebanking.com
Incident
- Discovered
- May 27, 2023
- Materiality determined
- Aug 7, 2023
- Notification sent
- Sep 7, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Third party
- via Progress Software Corp.
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(72 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.