HackingVulnerability ExploitSupply Chain (3P Vendor)TargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
BankGloucester
bd_bbcc8d64e8e7f5a4 · schema v1 · pii pii-v1
Full breach record for BankGloucester →BankGloucester notified consumers of a data breach affecting its third-party vendor, Darling Consulting Group, which used Progress Software's MOVEit Transfer. The vulnerability, disclosed May 31, 2023, allowed unauthorized access to data including names, SSNs, DOBs, and account numbers. BankGloucester offered 2 years of Equifax credit monitoring. No evidence of misuse was found.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_405d1174d081800bMaine State AGfiled 2023-08-22Candidate
- bd_8e3590d7e88b579fMontana State AGfiled 2023-08-22Verified
- bd_b7b3242cbacb7368New Hampshire State AGfiled 2023-08-22Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-22-bankgloucester-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2023
- Raw hash
- cfe494ec52f0a6da980913627deb54b74b913684d10d84e7648733841c03465a
Reporting entity
- Name
- BankGloucesternorm: bankgloucester
Victim entity
- Name
- BankGloucesternorm: bankgloucester
Incident
- Discovered
- Jul 12, 2023
- Materiality determined
- —
- Notification sent
- Aug 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via Darling Consulting Group
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.