HackingFINANCIAL_ACCOUNTPIILowContained
Savers Co-operative Bank
bd_bbf621a605a3c8b3 · schema v1 · pii pii-v1
Full breach record for Savers Co-operative Bank →Savers Bank notified Massachusetts residents of a suspected security breach involving a merchant's network that compromised debit card numbers. The breach was reported by MasterCard International. No fraudulent activity was confirmed, but affected cards were reissued. The notification provided instructions for card activation, destruction of old cards, and monitoring accounts. It also included guidance on credit reporting agencies, fraud alerts, and security freezes.
Massachusetts clock✓ MA AG ≤30d5 days discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_26348f2f1df491e5Massachusetts State AGfiled 2026-06-01Candidate
- bd_8a5b6fb6fa2acaccMassachusetts State AGfiled 2026-06-01Candidate
- bd_360e966706824cceMassachusetts State AGfiled 2026-07-01(30d gap)Candidate
- bd_4fb676c0d44bf70cMassachusetts State AGfiled 2026-07-01(30d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 31d gap
- bd_552579c934e54be6Massachusetts State AGfiled 2026-05-01(31d gap)Candidate
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-1015-savers-bank/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- a3b03f6323b81269a2f8476a0d8906e6e8adb5760b04478ab71805c28bafeaae
Reporting entity
- Name
- Savers Co-operative Banknorm: savers co operative bank
- Domain
- saversbank.com
Victim entity
- Name
- Savers Co-operative Banknorm: savers co operative bank
- Domain
- saversbank.com
Incident
- Discovered
- May 27, 2026
- Materiality determined
- —
- Notification sent
- May 27, 2026
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Third party
- via MasterCard International
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 days(5 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.