Woodsville Guaranty Savings Bank
bd_c124f866b83880fc · schema v1 · pii pii-v1
Full breach record for Woodsville Guaranty Savings Bank →Woodsville Guaranty Savings Bank (WGSB) notified 681 New Hampshire residents of a data breach involving its third-party vendor, Fiserv. The incident stemmed from vulnerabilities in Fiserv's MOVEit Transfer software, with unauthorized access occurring between May 27 and 31, 2023. WGSB was notified by Fiserv on August 8, 2023. The breach potentially exposed names and government-issued identifiers. WGSB engaged forensic specialists, notified law enforcement and regulators, terminated its relationship with Fiserv, and provided two years of complimentary credit monitoring through Kroll to affected individuals.
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_446f0dfe95f66ddbVermont State AGfiled 2024-01-05Verified
- bd_5bb447cbb3999d16Indiana State AGfiled 2024-01-05Verified
- bd_5d5382c52e10ff72Maine State AGfiled 2024-01-05Candidate
- bd_74c85f1bc1207032Montana State AGfiled 2024-01-05Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/woodsville-guaranty-savings-bank-20240105.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 5, 2024
- Raw hash
- 659222a5b06e2c859708a77cfdb98d1a39a351918d70601f8cd32fa2f46e57d0
Reporting entity
- Name
- Woodsville Guaranty Savings Banknorm: woodsville guaranty savings bank
Victim entity
- Name
- Woodsville Guaranty Savings Banknorm: woodsville guaranty savings bank
Incident
- Discovered
- Aug 8, 2023
- Materiality determined
- —
- Notification sent
- Jan 5, 2024
- Affected individuals
- 681
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcementNotified state and federal regulatorsProvided written notice to relevant state regulatorsNotified the three major credit reporting agencies (Equifax, Experian, and TransUnion)
- Third party
- via Fiserv
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 weeks(150 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.