HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
1st Source Bank
bd_fda2be588d043776 · schema v1 · pii pii-v1
Full breach record for 1st Source Bank →1st Source Bank filed a supplemental notice with the New Hampshire Attorney General regarding a MOVEit vulnerability incident. The bank became aware of the vulnerability on June 1, 2023, and confirmed customer PII was potentially acquired on June 24, 2023. 162 New Hampshire residents were notified. The bank partnered with Kroll to provide identity monitoring services.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_4a59c8811709f62bCalifornia State AGfiled 2023-07-26Verified
- bd_08c27ccfede4e9efOregon State AGfiled 2023-07-27(1d gap)Verified
- bd_d0cebba25691bccfWashington State AGfiled 2023-07-20(6d gap)Verified
- bd_db8e5883d0d70d12Oregon State AGfiled 2023-07-20(6d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 16d gap
- bd_504a71c703e7184fCalifornia State AGfiled 2023-07-19(7d gap)Verified
- bd_644846888cf47c7fMontana State AGfiled 2023-07-19(7d gap)Verified
- bd_ee5f8afdf477969eMaine State AGfiled 2023-07-19(7d gap)Verified
- bd_a872f10fb82b1c59Vermont State AGfiled 2023-07-14(12d gap)Candidate
- bd_66ec9f2d6644e603SEC 8-Kfiled 2023-07-10(16d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/first-source-20230726.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 26, 2023
- Raw hash
- 3a00d03fc5c58a94e9c85254e01cf3f37efd1c09b89ca684b7840da0117922ca
Reporting entity
- Name
- 1st Source Banknorm: 1st source bank
Victim entity
- Name
- 1st Source Banknorm: 1st source bank
Incident
- Discovered
- Jun 1, 2023
- Materiality determined
- Jun 24, 2023
- Notification sent
- Jul 14, 2023
- Affected individuals
- 162
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General John M. Formella
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.