DisclosureLens
HackingFinancial ServicesFinanceSupply Chain (3P Vendor)Customer Data InvolvedFinancial accountFinancial credentialsMediumResolved

Rockland Trust Company

bd_ade58be497710be1 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jun 13, 2023

Filed

Jul 25, 2023

To disclose

6 weeks

Affected · nationwide

11,66118 in this filing

Linked

9 filings

Confidence

50%
Full breach record for Rockland Trust Company →269 incidents on file

Rockland Trust Company reported a data breach affecting 18 Maine residents, which occurred between May 27 and May 31, 2023. The breach was discovered on June 13, 2023, and was caused by an incident at a third-party vendor. The compromised information includes financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. Affected individuals were notified on July 10, 2023, and offered 24 months of complimentary credit monitoring and fraud protection services through Experian.

Maine clockDiscovered Jun 13, 2023 → Filed with AG Jul 25, 202342d ⏱ ME AG >30d6 weeks discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 17 days
discovery → filing · 6 weeks / 42 days

May 27, 2023

Begins

Jun 13, 2023

Discovered

Jul 25, 2023

Filed

vs. sector median

4 wks faster

This filing is one of 9 filings about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (8) · sorted by filing gap

Show 4 more filings ↓up to 15d gap

Filing propagation · 9 filings · 4 states

View merged incident ↗

Pattern: first filing Jul 10 (VT), last Jul 27 (MA) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.