HackingVulnerability ExploitSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
Merrick Bank
bd_f1269d86626ef268 · schema v1 · pii pii-v1
Full breach record for Merrick Bank →Merrick Bank notified customers of a data breach involving MOVEit Transfer software. Unauthorized actors exploited a vulnerability in the software between May 27 and May 31, 2023, obtaining files containing personal information. The bank launched an investigation, patched systems, and offered two years of identity monitoring through Kroll.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_00a168f8fa2195eaMontana State AGfiled 2023-12-28Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578522
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 28, 2023
- Raw hash
- 8b1a1bcaa1326cf788b406ab95436936754fe81b0a147cc57873219d7eb44777
Reporting entity
- Name
- Merrick Banknorm: merrick bank
Victim entity
- Name
- Merrick Banknorm: merrick bank
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified regulatory bodies as required
- Third party
- via Progress Software
- Initial access
- supply_chain
Compliance
- Time to disclose
- 30 weeks(211 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.