BankGloucester
bd_b7b3242cbacb7368 · schema v1 · pii pii-v1
Full breach record for BankGloucester →2 incidents on fileBankGloucester notified the NH Attorney General of a security incident affecting 327 NH residents. The breach originated from a third-party vendor, Darling Consulting Group (DCG), which was compromised via the MOVEit Transfer software vulnerability (exploit_vuln) around May 30-31, 2023. BankGloucester detected the incident on July 12, 2023, upon notification from DCG. The investigation concluded on August 16, 2023, confirming the exposure of personal information. Notifications were mailed on August 22, 2023, offering 2 years of Equifax credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 12, 2023
Discovered
Aug 16, 2023
Scope determined
Aug 22, 2023
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_29b3b4e1a9e0fff92023-08-22Verified
- Maine State AGbd_405d1174d081800b2023-08-22Candidate
- Montana State AGbd_8e3590d7e88b579f2023-08-22Verified
- Vermont State AGbd_bbcc8d64e8e7f5a42023-08-22Verified
Filing propagation · 5 filings · 5 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.