DisclosureLens
FEDERALItem 8.01 · voluntaryHackingFinancial ServicesFinanceVulnerability ExploitZero-DayData ExfiltratedSupply Chain (3P Vendor)PIILowActive

Sunflower Bank, National Association

bd_d36ee2ad177829e8 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 31, 2023

Filed

Jul 14, 2023

To disclose

6 weeks

Affected

Not disclosed

Linked

8 filings

Confidence

67%
Full breach record for Sunflower Bank, National Association

FirstSun Capital Bancorp reported that its subsidiary, Sunflower Bank, N.A., was impacted by a zero-day vulnerability in Progress Software's MOVEit file transfer software. An unauthorized party likely downloaded files containing PII from the MOVEit server. The bank engaged forensic experts and applied vendor patches. The investigation is ongoing, and the Bank reported no material interruption to its business operations.

Incident timeline

discovery → filing · 6 weeks / 44 days

May 31, 2023

Discovered

Jul 14, 2023

Filed

vs. sector median

2 wks faster

This filing is one of 8 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 82d gap

Filing propagation · 8 filings · 5 states

View merged incident ↗

Pattern: first filing Jul 14, last Oct 4 (CA) — a 82-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.