HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
BankGloucester
bd_b7b3242cbacb7368 · schema v1 · pii pii-v1
Full breach record for BankGloucester →BankGloucester notified the NH Attorney General of a security incident affecting 327 NH residents. The breach originated from a third-party vendor, Darling Consulting Group (DCG), which was compromised via the MOVEit Transfer software vulnerability (exploit_vuln) around May 30-31, 2023. BankGloucester detected the incident on July 12, 2023, upon notification from DCG. The investigation concluded on August 16, 2023, confirming the exposure of personal information. Notifications were mailed on August 22, 2023, offering 2 years of Equifax credit monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_405d1174d081800bMaine State AGfiled 2023-08-22Candidate
- bd_8e3590d7e88b579fMontana State AGfiled 2023-08-22Verified
- bd_bbcc8d64e8e7f5a4Vermont State AGfiled 2023-08-22Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bankgloucester-20230822.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2023
- Raw hash
- b687491f6e5b5fda902f6da1d5d41c24ae91ebb03017d801f9ff6031b1c1c74b
Reporting entity
- Name
- BankGloucesternorm: bankgloucester
Victim entity
- Name
- BankGloucesternorm: bankgloucester
Incident
- Discovered
- Jul 12, 2023
- Materiality determined
- Aug 16, 2023
- Notification sent
- Aug 22, 2023
- Affected individuals
- 327
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Darling Consulting Group
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.