HackingVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICCVE-2023-3462LowContained
The Huntington National Bank
bd_b3d9698efebd17ae · schema v1 · pii pii-v1
Full breach record for The Huntington National Bank →Alogent Holdings, Inc. disclosed a data breach affecting customer data processed for Huntington Bank. Between May 30 and June 1, 2023, an unauthorized party exploited a zero-day vulnerability (CVE-2023-3462) in Progress Software's MOVEit Transfer application, a third-party vendor solution. Exposed data included account and routing numbers, names, addresses, phone numbers, check payees, and remittance amounts. Alogent discontinued the use of the affected software and is offering identity theft protection services through IDX.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574245
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 26, 2023
- Raw hash
- 50f574b8e4f61eebe3c5b8a852e43de87d83b2ccf507d1ccaf76c0fa19354608
Reporting entity
- Name
- Alogentnorm: alogent
Victim entity
- Name
- The Huntington National Banknorm: the huntington national bank
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
- CVE references
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.