Social EngineeringFinancial ServicesFinancePhishingStolen CredentialsCustomer Data InvolvedTargetedPIILowContained
Reading Cooperative Bank
bd_b84836cd62e897a2 · schema v1 · pii pii-v1
Full breach record for Reading Cooperative Bank →Reading Cooperative Bank (RCB), a financial institution in Reading, MA, experienced a phishing-related security incident on August 8, 2024, discovered January 31, 2025. A bank employee clicked a phishing email from a known sender at a business partner organization. Personally identifiable information of 24,041 individuals (89 Maine residents) may have been compromised. RCB engaged third-party experts, secured its systems, and offered 24 months of Experian IdentityWorks to affected individuals.
Maine clockDiscovered Jan 31, 2025 → Filed with AG Feb 24, 202524d ✓ ME AG ≤30d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_02dea8362f280694Maryland State AGfiled 2025-02-24Verified
- bd_03550ed043b521c4Vermont State AGfiled 2025-02-24Verified
- bd_286bccc460c3cdadNew Hampshire State AGfiled 2025-02-24Verified
- bd_c359101a4dbd2ec0Indiana State AGfiled 2025-02-24Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/9ea6cc74-3259-495c-88c6-4f7594256001.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 24, 2025
- Raw hash
- b7caaf365d4020cf4ebd63071f9031bdaafa25876e7cdf5ebbc655655137b967
Reporting entity
- Name
- Reading Cooperative Banknorm: reading cooperative bank
- Domain
- readingcoop.com
- Industry
- Financial Services
Victim entity
- Name
- Reading Cooperative Banknorm: reading cooperative bank
- Domain
- readingcoop.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Jan 31, 2025
- Materiality determined
- —
- Notification sent
- Feb 24, 2025
- Affected individuals
- 89
- Data types
- PII
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Jan 31, 2025→ Filed with AG: Feb 24, 202524d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.