HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
1st Source Bank
bd_d3b9e2557a659262 · schema v1 · pii pii-v1
Full breach record for 1st Source Bank →1st Source Bank notified customers that their personal information, including names and Social Security numbers, may have been acquired without authorization due to a critical vulnerability in the MOVEit file transfer software provided by Progress Software. The bank became aware of the alert on June 1, 2023, and patched the system. The breach date listed by the CA AG is May 27, 2023. The bank engaged cybersecurity experts and is offering 12 months of identity monitoring via Kroll.
California clockDiscovered Jun 1, 2023 → Notified Oct 27, 2023148d ✗ CA 60-day late26 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_3d177f54ec92c990HHS OCRfiled 2023-11-20(8d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-577160
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 28, 2023
- Raw hash
- 6494517b915dd4e635a5735ad2fddef1ca4917c45a4b1f5079703d02dc15ba2c
Reporting entity
- Name
- 1st Source Banknorm: 1st source bank
Victim entity
- Name
- 1st Source Banknorm: 1st source bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- —
- Notification sent
- Oct 27, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 26 weeks(180 days from discovery to filing)
- Compliance flags
- CA 60-day late · 148d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 1, 2023→ Notified: Oct 27, 2023148d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.