HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSMediumContained
Northfield Bank
bd_d86ff387ddb8a86a · schema v1 · pii pii-v1
Full breach record for Northfield Bank →Northfield Bank notified Vermont consumers of a data security event involving its third-party vendor, Progress Software Corporation. The incident, occurring May 27-31, 2023, exploited vulnerabilities in the MOVEit Transfer application. Affected data included names, account numbers, SSNs, and online banking usernames. No passwords were compromised. Northfield Bank engaged cybersecurity specialists and the vendor patched systems. Affected individuals received two years of complimentary identity monitoring through Kroll.
Vermont clock⏱ VT AG >14 bday7 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_d9885b4724d48106New Hampshire State AGfiled 2023-10-02(7d gap)Verified
- bd_9963040c41fa4926New Hampshire State AGfiled 2023-09-08(17d gap)Verified
- bd_e04b124b7a8d579eVermont State AGfiled 2023-09-08(17d gap)Candidate
- bd_79fd0089944d1124Maine State AGfiled 2023-09-07(18d gap)Candidate
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-25-northfield-bank-progress-software-moveit-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 25, 2023
- Raw hash
- 8a6b41d12b96b4ef7c4922f4b804fc742fc6ac238c6c9baa11be09eb88e60460
Reporting entity
- Name
- Northfield Banknorm: northfield bank
Victim entity
- Name
- Northfield Banknorm: northfield bank
Incident
- Discovered
- Aug 4, 2023
- Materiality determined
- —
- Notification sent
- Sep 25, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- supply_chain
Compliance
- Time to disclose
- 7 weeks(52 days from discovery to filing)
- Compliance flags
- VT AG >14 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.