MalwareRansomwareData EncryptedRansom DemandedIDENTITY_BASICCREDENTIALSLowContained
Tri Counties Bank
bd_af220720d4d00291 · schema v1 · pii pii-v1
Full breach record for Tri Counties Bank →Tri Counties Bank notified consumers of a ransomware incident discovered on Feb 7, 2023. The attack encrypted files and compromised systems between Feb 7-8, 2023. Affected data included names and credentials. The bank engaged third-party forensic specialists, notified law enforcement, and offered 24 months of credit monitoring. No identity theft was confirmed.
Vermont clock✗ VT AG >45 bday41 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by black_basta about this victim predates this filing by 247 days.View originating leak claim
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_3d1dd695dbfc9eb9New Hampshire State AGfiled 2023-11-22Verified
- bd_9d8a5b82fc79f500California State AGfiled 2023-11-22Verified
- bd_201ae7fa1e3c8a63Maine State AGfiled 2023-10-12(41d gap)Candidate
- bd_3f1547cf3ba03ec1Montana State AGfiled 2023-10-12(41d gap)Verified by operator
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-11-22-tri-counties-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 22, 2023
- Raw hash
- 9db11256b11573b3f59cd561030bae7e5ff4f487dba3f2989df0dbc8263bee00
Reporting entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Victim entity
- Name
- Tri Counties Banknorm: tri counties bank
- Domain
- tcbk.com
Incident
- Discovered
- Feb 7, 2023
- Materiality determined
- Nov 22, 2023
- Notification sent
- Nov 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- notified applicable regulatory authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 41 weeks(288 days from discovery to filing)
- Compliance flags
- VT AG >45 bdayLeak >180d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.