HackingVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIDENTITY_BASICLowContained
Sunflower Bank, National Association
bd_ef42af6291b75a20 · schema v1 · pii pii-v1
Full breach record for Sunflower Bank, National Association →Sunflower Bank, N.A. notified the NH AG of a data incident involving the MOVEit software zero-day vulnerability. The bank received notice from vendor Progress Software on May 31, 2023. An unauthorized party likely downloaded files from the bank's segmented MOVEit server. 23 New Hampshire residents were affected. The bank engaged forensic experts, applied vendor fixes, and mailed notices offering credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_895de35e1cea98f0California State AGfiled 2023-08-15Verified
- bd_d36ee2ad177829e8SEC 8-Kfiled 2023-07-14(32d gap)Verified
- bd_46ae3c2793a32792New Hampshire State AGfiled 2023-10-02(48d gap)Verified
- bd_fea17e438a10a5c6California State AGfiled 2023-10-04(50d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/sunflower-bank-20230815.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 15, 2023
- Raw hash
- ee04de51fa3a0476726b0e7dc889639d623d6ee263517f96a5d20b419aecc68f
Reporting entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
Victim entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
Incident
- Discovered
- May 31, 2023
- Materiality determined
- Jul 14, 2023
- Notification sent
- Aug 14, 2023
- Affected individuals
- 23
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(76 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.