DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitZero-DaySupply Chain (3P Vendor)Customer Data InvolvedFinancial accountIdentity (basic)CVE-2023-3462LowContained

Alogent

bd_b3d9698efebd17ae · schema v1 · pii pii-v1

Severity

Low

Discovered

—

Filed

Sep 26, 2023

To disclose

—

Affected

Not disclosed

Linked

10 records

Confidence

66%
Full breach record for Alogent →

Alogent Holdings, Inc. disclosed a data breach affecting customer data processed for Huntington Bank. Between May 30 and June 1, 2023, an unauthorized party exploited a zero-day vulnerability (CVE-2023-3462) in Progress Software's MOVEit Transfer application, a third-party vendor solution. Exposed data included account and routing numbers, names, addresses, phone numbers, check payees, and remittance amounts. Alogent discontinued the use of the affected software and is offering identity theft protection services through IDX.

Leak gap clock⏱ Leak >30d
⚠ no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

May 30, 2023

Begins

Sep 26, 2023

Filed

This filing is one of 10 records about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →
A leak claim by cl0p about this victim was first seen 62 days before this filing.View originating leak claim

Linked disclosures

Why this link?

Ransomware claims (1)

Regulatory filings (8) · sorted by filing gap

Show 4 more filings ↓up to 268d gap

Filing propagation · 9 filings · 8 states

View merged incident ↗
Illinois State AGJan 1 · first
California State AG+268d · this page

Pattern: first filing Jan 1 (IL), last Sep 26 (CA) — a 268-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.