Social EngineeringPhishingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_BASICCREDENTIALSLowContained
Limestone Bank, Inc.
bd_e69f36a77ffb01dd · schema v1 · pii pii-v1
Full breach record for Limestone Bank, Inc. →Limestone Bank (now merged into Peoples Bank) notified consumers of a data security incident involving unauthorized access to an employee email account between November 21, 2022, and March 23, 2023. The breach was caused by phishing leading to credential compromise. Affected data included names and other personal information. The bank engaged a cybersecurity firm, secured the account, and offered credit monitoring services.
Vermont clock✗ VT AG >45 bday43 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-09-15-limestone-bank-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2023
- Raw hash
- 608716f0a6e02df542637f2c67250a970dbe519c369160b6a3022555512bf94b
Reporting entity
- Name
- Limestone Bank, Inc.norm: limestone bank
Victim entity
- Name
- Limestone Bank, Inc.norm: limestone bank
Incident
- Discovered
- Nov 21, 2022
- Materiality determined
- —
- Notification sent
- Sep 15, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed notice with the Office of the Vermont Attorney General
- Initial access
- phishing_link
Compliance
- Time to disclose
- 43 weeks(298 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.