HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
MASCOMA BANK
bd_bf39a0453b59673a · schema v1 · pii pii-v1
Full breach record for MASCOMA BANK →Mascoma Bank notified consumers of a data breach involving its third-party vendor, MOVEit Transfer. Data copied on May 30, 2023, included names and Social Security numbers. Mascoma Bank offered 12 months of credit monitoring and is issuing new account numbers. The incident was discovered on July 12, 2023.
Vermont clock⏱ VT AG >14 bday6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-25-mascoma-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2023
- Raw hash
- 3054901552c0849cd5d3d7b696e32e7798309e1196cb942f79d43686d0fd565a
Reporting entity
- Name
- MASCOMA BANKnorm: mascoma bank
- Industry
- financial_services
Victim entity
- Name
- MASCOMA BANKnorm: mascoma bank
- Industry
- financial_services
Incident
- Discovered
- Jul 12, 2023
- Materiality determined
- —
- Notification sent
- Aug 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.