HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedSupply Chain (Dependency)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
City National Bank of Florida
bd_e4a5de2e9c6485cf · schema v1 · pii pii-v1
Full breach record for City National Bank of Florida →City National Bank of Florida (CNBF) issued a supplemental notice regarding a MOVEit Transfer zero-day vulnerability incident. Unauthorized access occurred May 29-30, 2023. CNBF discovered the incident on June 3, 2023. Data exposed included names, DOB, SSNs, and bank account numbers. CNBF notified 18 New Hampshire residents and offered credit monitoring. The filing is a follow-up to an initial June 30, 2023 notification.
Leak gap clock✗ Leak >180d8 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
A leak claim by dispossessor about this victim predates this filing by 604 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (1)
- bd_570679dab11b4556Leak Sitecl0pfiled 2023-06-30(31d gap)Candidate
Regulatory filings (1) · sorted by filing gap
- bd_29d5c53f10db8353Maine State AGfiled 2023-08-07(7d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/city-national-bank-of-florida-20230731.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2023
- Raw hash
- ba257c1c8e5e73d17ad5643da3bed391792745db4b1db9a8fd4897d12a06d885
Reporting entity
- Name
- City National Bank of Floridanorm: city national bank of florida
- Domain
- citynational.com
Victim entity
- Name
- City National Bank of Floridanorm: city national bank of florida
- Domain
- citynational.com
Incident
- Discovered
- Jun 3, 2023
- Materiality determined
- —
- Notification sent
- Jun 30, 2023
- Affected individuals
- 18
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified federal law enforcement authoritiesNotified federal regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(58 days from discovery to filing)
- Compliance flags
- Leak >180d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.