Sunflower Bank, National Association
bd_ef42af6291b75a20 · schema v1 · pii pii-v1
Full breach record for Sunflower Bank, National Association →Sunflower Bank, N.A. notified the NH AG of a data incident involving the MOVEit software zero-day vulnerability. The bank received notice from vendor Progress Software on May 31, 2023. An unauthorized party likely downloaded files from the bank's segmented MOVEit server. 23 New Hampshire residents were affected. The bank engaged forensic experts, applied vendor fixes, and mailed notices offering credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
May 31, 2023
Discovered
Jul 14, 2023
Scope determined
Aug 15, 2023
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- California State AGbd_895de35e1cea98f02023-08-15Verified
- Montana State AGbd_b791064e55b0bfd82023-08-15Verified
- Indiana State AGbd_791c96ad5aceed032023-08-14 · +1dVerified
- Massachusetts State AGbd_57054109e6719b1e2023-08-22 · +7dVerified
Show 3 more filings ↓Show fewer ↑up to 50d gap
- SEC 8-Kbd_d36ee2ad177829e82023-07-14 · +32dVerified
- New Hampshire State AGbd_46ae3c2793a327922023-10-02 · +48dVerified
- California State AGbd_fea17e438a10a5c62023-10-04 · +50dVerified
Filing propagation · 8 filings · 5 states
View merged incident ↗Pattern: first filing Jul 14, last Oct 4 (CA) — a 82-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.