MalwareRansomwareStolen CredentialsDaixinRansom DemandedData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedMulti-Stage ChainIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Webster Bank, National Association
bd_b26f4a157e67d25b · schema v1 · pii pii-v1
Full breach record for Webster Bank, National Association →Webster Bank, N.A. notified the New Hampshire Attorney General of a third-party vendor breach involving Guardian Analytics, Inc. A ransomware attack (Daixin/LockBit) on Guardian's systems between Nov 27, 2022 and Jan 17, 2023 resulted in the exfiltration and encryption of Webster customer data. Webster discovered the incident on Jan 26, 2023. 348 New Hampshire residents were affected, with data including names, account numbers, and potentially SSNs. Webster offered 24 months of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_8dd6fb8c661b3b58Maine State AGfiled 2023-04-10(2d gap)Candidate
- bd_fd452c6f18b5b1e9Montana State AGfiled 2023-04-10(2d gap)Verified
- bd_519c51969ff5e987Maine State AGfiled 2023-04-28(16d gap)Verified
- bd_8b98ad645053816cNew Hampshire State AGfiled 2023-05-03(21d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/webster-bank-20230412.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 12, 2023
- Raw hash
- abc6c8115f3ae422dcd270cbb9c6860784260b1f3ef4fcb1c956f9d726bf9c55
Reporting entity
- Name
- Webster Bank, National Associationnorm: webster bank national
Victim entity
- Name
- Webster Bank, National Associationnorm: webster bank national
Incident
- Discovered
- Jan 26, 2023
- Materiality determined
- Feb 10, 2023
- Notification sent
- Apr 10, 2023
- Affected individuals
- 348
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid AccountsT1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- DaixinExternalFinancial
- Regulator citations
- Provided preliminary notice to the Office of the Comptroller of the Currency ("OCC")Provided preliminary notice to the Federal Reserve Board of New York ("FRB NY")Guardian notified law enforcement and is cooperating with their investigation
- Third party
- via Guardian Analytics, Inc.
- Initial access
- external_remote_services
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.