HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICPIILowContained
Hanmi Bank
bd_a6c722dbb4e853f6 · schema v1 · pii pii-v1
Full breach record for Hanmi Bank →Hanmi Bank notified customers of a data breach involving its third-party vendor, Fiserv, which used MOVEit Transfer software. Unauthorized actors exploited vulnerabilities in the software to access files between May 27 and May 31, 2023. Affected data may include names and other personal information. Hanmi Bank engaged in investigation, reviewed impacted individuals, and offered two years of identity monitoring through Kroll. The vendor patched systems and remediated vulnerabilities.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-579424
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2024
- Raw hash
- f73283d4a581ec4a8e7f981085ad64d5f4fbf7ac4ee9517c08729fd1a71c7d56
Reporting entity
- Name
- Hanmi Banknorm: hanmi bank
Victim entity
- Name
- Hanmi Banknorm: hanmi bank
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified regulatory bodies as required
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.