FEDERALItem 8.01 · voluntaryHackingVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)PIILowActive
Sunflower Bank, National Association
bd_d36ee2ad177829e8 · schema v1 · pii pii-v1
Full breach record for Sunflower Bank, National Association →FirstSun Capital Bancorp reported that its subsidiary, Sunflower Bank, N.A., was impacted by a zero-day vulnerability in Progress Software's MOVEit file transfer software. An unauthorized party likely downloaded files containing PII from the MOVEit server. The bank engaged forensic experts and applied vendor patches. The incident is ongoing with no material business interruption reported.
SEC clockMateriality determined Jul 14, 2023 → Filed Jul 14, 20230d ✓ SEC 4-day OK6 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_895de35e1cea98f0California State AGfiled 2023-08-15(32d gap)Verified
- bd_ef42af6291b75a20New Hampshire State AGfiled 2023-08-15(32d gap)Verified
- bd_fea17e438a10a5c6California State AGfiled 2023-10-04(82d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1709442/000170944223000014/
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jul 14, 2023
- Raw hash
- 00e9e6e737be6f57b4f90f0de9d3c19ce368ae3e1a3328f85799a0b3514a0036
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- FIRSTSUN CAPITAL BANCORPnorm: firstsun capital bancorp
- SEC CIK
- 0001709442
Victim entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jul 14, 2023
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 6 weeks(44 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jul 14, 2023→ Filed: Jul 14, 20230d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.