PhysicalTheftData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Eastern Bank
bd_e9d2caae4c21c0a8 · schema v1 · pii pii-v1
Full breach record for Eastern Bank →New Hampshire Attorney General received notification from Eastern Bank regarding a carjacking of a third-party courier service on April 5, 2016. Stolen courier bags contained documentation with personal information of one New Hampshire-based business accountholder, including names, addresses, bank account numbers, and routing numbers. No evidence of misuse was found as of May 23, 2016.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/eastern-bank-20160523.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 23, 2016
- Raw hash
- 8c487417523c035f452ee703cec608e82abdc0a77847566c117a778b03c860e9
Reporting entity
- Name
- Eastern Banknorm: eastern bank
- Domain
- easternbank.com
Victim entity
- Name
- Eastern Banknorm: eastern bank
- Domain
- easternbank.com
Incident
- Discovered
- Apr 20, 2016
- Materiality determined
- —
- Notification sent
- May 23, 2016
- Affected individuals
- 1
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Third party
- via third-party courier serviceaffiliate bank vendor
Compliance
- Time to disclose
- 5 weeks(33 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.