DisclosureLens
MalwareFinancial ServicesFinanceRansomwareCustomer Data InvolvedData EncryptedRansom DemandedPIIIdentity (basic)Government IDCritical

1st Source Bank

bd_ee5f8afdf477969e · schema v1 · pii pii-v1

Severity

Critical

Discovered

Jun 1, 2023

Filed

Jul 19, 2023

To disclose

7 weeks

Affected · nationwide

450,00090 in this filing

Linked

10 filings

Confidence

65%
Full breach record for 1st Source Bank →6 incidents on file

1st Source Bank reported a ransomware incident that was discovered on June 1, 2023. The breach impacted approximately 450,000 individuals, compromising their names and Social Security numbers. The bank began notifying affected parties on July 14, 2023, and offered 12 months of identity monitoring services through Kroll.

Maine clockDiscovered Jun 1, 2023 → Filed with AG Jul 19, 202348d ⏱ ME AG >30d7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 7 weeks / 48 days

Jun 1, 2023

Begins

Jun 1, 2023

Discovered

Jul 19, 2023

Filed

vs. sector median

3 wks faster

This filing is one of 10 filings about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (9) · sorted by filing gap

Show 5 more filings ↓up to 9d gap

Filing propagation · 10 filings · 7 states

View merged incident ↗

Pattern: first filing Jul 10, last Jul 27 (OR) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.