HackingVulnerability ExploitSupply Chain (3P Vendor)TargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
1st Source Bank
bd_a872f10fb82b1c59 · schema v1 · pii pii-v1
Full breach record for 1st Source Bank →1st Source Bank notified Vermont consumers of a data breach linked to the MOVEit file transfer software vulnerability. The incident, discovered June 1, 2023, potentially exposed names, SSNs, driver's license numbers, and dates of birth. The bank patched its system, engaged forensic experts, and offered 12 months of identity monitoring through Kroll.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_66ec9f2d6644e603SEC 8-Kfiled 2023-07-10(4d gap)Candidate
- bd_504a71c703e7184fCalifornia State AGfiled 2023-07-19(5d gap)Verified
- bd_644846888cf47c7fMontana State AGfiled 2023-07-19(5d gap)Verified
- bd_ee5f8afdf477969eMaine State AGfiled 2023-07-19(5d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 13d gap
- bd_d0cebba25691bccfWashington State AGfiled 2023-07-20(6d gap)Verified
- bd_db8e5883d0d70d12Oregon State AGfiled 2023-07-20(6d gap)Verified
- bd_4a59c8811709f62bCalifornia State AGfiled 2023-07-26(12d gap)Verified
- bd_fda2be588d043776New Hampshire State AGfiled 2023-07-26(12d gap)Verified
- bd_08c27ccfede4e9efOregon State AGfiled 2023-07-27(13d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-07-14-1st-source-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2023
- Raw hash
- aeae51c30f0c315bddd6d656db21d7eec662da7b5e22fb655820d67b482a69ee
Reporting entity
- Name
- 1st Source Banknorm: 1st source bank
Victim entity
- Name
- 1st Source Banknorm: 1st source bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Jul 14, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(43 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.