DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitSupply Chain (3P Vendor)Zero-DayCustomer Data InvolvedPIIIdentity (basic)LowContained

PlainsCapital Bank

bd_d0fa7306adbe4d64 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jun 27, 2023

Filed

Jul 14, 2023

To disclose

17 days

Affected

48state residents only

Linked

4 filings

Confidence

65%
Full breach record for PlainsCapital Bank2 incidents on file

PlainsCapital Bank notified customers of a data breach stemming from a third-party vendor's exposure to the MOVEit zero-day cyberattack. The incident, discovered on June 27, 2023, likely impacted customer personal information. The Bank investigated, engaged the vendor to apply security patches, and offered 12 months of complimentary credit monitoring and identity restoration services to affected individuals.

Incident timeline

discovery → filing · 17 days

Jun 27, 2023

Begins

Jun 27, 2023

Discovered

Jul 14, 2023

Filed

vs. sector median

6 wks faster

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 3 states

View merged incident ↗
SEC 8-KJul 3 · first
Montana State AG+11d · this page

Pattern: first filing Jul 3, last Jul 14 (MT) — a 11-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.