Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedDelayed DiscoveryPIIIDENTITY_BASICIDENTITY_GOVERNMENTMediumResolved
GreatBanc Trust Company
bd_b77fafab2a9b0123 · schema v1 · pii pii-v1
Full breach record for GreatBanc Trust Company →GreatBanc Trust Company, serving as ESOP trustee, experienced an email phishing attack during the week of October 23, 2017. An unauthorized third party accessed one of GreatBanc's email accounts and created a folder to redirect wire-transfer-related emails. An email account review determined personal information (name, address, date of birth, and/or SSN) of plan participants was contained in the account. Notification letters were sent in June 2018. Remediation included 2FA implementation and staff training.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-137157
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 15, 2018
- Raw hash
- 435568ea8d564b8b9088e280dc73575f45c3381697721a638caaf81885e662b1
Reporting entity
- Name
- GreatBanc Trust Companynorm: greatbanc trust
- Domain
- greatbanctrust.com
Victim entity
- Name
- GreatBanc Trust Companynorm: greatbanc trust
- Domain
- greatbanctrust.com
- Industry
- Financial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.