HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
KeyBank National Association
bd_b28da354340c3c8c · schema v1 · pii pii-v1
Full breach record for KeyBank National Association →KeyBank disclosed a data breach involving its third-party vendor, Overby-Seawell Company (OSC). On July 5, 2022, an unauthorized external party gained remote access to OSC's network and acquired KeyBank client mortgage information, including names, addresses, account numbers, phone numbers, and the first eight digits of Social Security numbers. KeyBank was notified on August 4, 2022. The incident did not affect KeyBank's own systems. OSC engaged third-party experts, notified the FBI, and provided affected clients with two years of Equifax credit monitoring.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_770a2169c5d0839cWashington State AGfiled 2022-08-26Candidate
- bd_f081eecb38503eeeMontana State AGfiled 2022-08-26Verified
- bd_6ac2e700788c603bOregon State AGfiled 2022-08-30(4d gap)Verified
- bd_204b30c931f55115Oregon State AGfiled 2022-10-21(56d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 56d gap
- bd_a4f654df6f257b9bCalifornia State AGfiled 2022-10-21(56d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-556679
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 26, 2022
- Raw hash
- b5fb9a420761f6898b74f093bdef1777a046ec3f4d3e28a8c42232e23cc4f099
Reporting entity
- Name
- KeyBank National Associationnorm: keybank national
Victim entity
- Name
- KeyBank National Associationnorm: keybank national
Incident
- Discovered
- Aug 4, 2022
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation (FBI)
- Third party
- via Overby-Seawell Company (OSC)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.