DisclosureLens
HackingFinancial ServicesFinanceVulnerability ExploitZero-DayData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)PIIIdentity (basic)LowContained

Sunflower Bank, National Association

bd_ef42af6291b75a20 · schema v1 · pii pii-v1

Severity

Low

Discovered

May 31, 2023

Filed

Aug 15, 2023

To disclose

11 weeks

Affected

23state residents only

Linked

8 filings

Confidence

66%
Full breach record for Sunflower Bank, National Association

Sunflower Bank, N.A. notified the NH AG of a data incident involving the MOVEit software zero-day vulnerability. The bank received notice from vendor Progress Software on May 31, 2023. An unauthorized party likely downloaded files from the bank's segmented MOVEit server. 23 New Hampshire residents were affected. The bank engaged forensic experts, applied vendor fixes, and mailed notices offering credit monitoring.

Incident timeline

discovery → filing · 11 weeks / 76 days

May 31, 2023

Discovered

Jul 14, 2023

Scope determined

Aug 15, 2023

Filed

vs. sector median

+2 wks slower

This filing is one of 8 about the same incident.View merged incident
Part of Progress Software Corporation supply-chain incident (2023) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 50d gap

Filing propagation · 8 filings · 5 states

View merged incident ↗

Pattern: first filing Jul 14, last Oct 4 (CA) — a 82-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.