HackingStolen CredentialsSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICLowContained
Primis Bank
bd_c07f6e12ea145ee6 · schema v1 · pii pii-v1
Full breach record for Primis Bank →Primis Bank notified the New Hampshire Attorney General of a third-party data breach involving vendor Darling Consulting. Unauthorized actors exploited a MOVEit vulnerability to download files containing personal information of 9 NH residents between May 30-31, 2023. Primis discovered the incident on July 24, 2023, and notified affected individuals on August 24, 2023, offering credit monitoring services.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_a8bbcd974af078beMaine State AGfiled 2023-08-24Candidate
- bd_db0235daa743179eMontana State AGfiled 2023-08-24Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/primis-bank-20230824.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 24, 2023
- Raw hash
- c519049037a53bb4c33496947145272ebbdb53f25c10ccf6c5df7bf37973b3f8
Reporting entity
- Name
- Primis Banknorm: primis bank
Victim entity
- Name
- Primis Banknorm: primis bank
Incident
- Discovered
- Jul 24, 2023
- Materiality determined
- —
- Notification sent
- Aug 24, 2023
- Affected individuals
- 9
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John Formella
- Third party
- via Darling Consulting
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(31 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.