Northfield Bank
bd_d86ff387ddb8a86a · schema v1 · pii pii-v1
Full breach record for Northfield Bank →Northfield Bank notified Vermont consumers of a data security event involving its third-party vendor, Progress Software Corporation. The incident, occurring May 27-31, 2023, exploited vulnerabilities in the MOVEit Transfer application. Affected data included names, account numbers, SSNs, and online banking usernames. No passwords were compromised. Northfield Bank engaged cybersecurity specialists and the vendor patched systems. Affected individuals received two years of complimentary identity monitoring through Kroll.
J jump to incidentP pin to compareR raw source
Incident timeline
May 27, 2023
Begins
Aug 4, 2023
Discovered
Sep 25, 2023
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Indiana State AGbd_2d7bc11eba226abc2023-09-25Verified
- New Hampshire State AGbd_d9885b4724d481062023-10-02 · +7dVerified
- Massachusetts State AGbd_05cc028fdb8910792023-09-08 · +17dVerified
- New Hampshire State AGbd_9963040c41fa49262023-09-08 · +17dVerified
Show 2 more filings ↓Show fewer ↑up to 18d gap
- Vermont State AGbd_e04b124b7a8d579e2023-09-08 · +17dCandidate
- Maine State AGbd_79fd0089944d11242023-09-07 · +18dCandidate
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing Sep 7 (ME), last Oct 2 (NH) — a 25-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.