HackingVulnerability ExploitSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Sunflower Bank, National Association
bd_fea17e438a10a5c6 · schema v1 · pii pii-v1
Full breach record for Sunflower Bank, National Association →Sunflower Bank, N.A. notified customers of a security incident involving a vulnerability in Progress Software's MOVEit file transfer software. The bank was notified of the vulnerability on May 31, 2023. The incident potentially exposed first and last names and financial transaction information. The bank engaged forensic experts, applied patches, and offered credit monitoring.
California clockDiscovered May 31, 2023 → Notified Sep 27, 2023119d ✗ CA 60-day late18 weeks discovery → filing
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_46ae3c2793a32792New Hampshire State AGfiled 2023-10-02(2d gap)Verified
- bd_895de35e1cea98f0California State AGfiled 2023-08-15(50d gap)Verified
- bd_ef42af6291b75a20New Hampshire State AGfiled 2023-08-15(50d gap)Verified
- bd_d36ee2ad177829e8SEC 8-Kfiled 2023-07-14(82d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-574636
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 4, 2023
- Raw hash
- a64e27a2f7c7fe6c6d17c06a9034255e36eec914e968b53c005ce987d700b437
Reporting entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
Victim entity
- Name
- Sunflower Bank, National Associationnorm: sunflower bank national
Incident
- Discovered
- May 31, 2023
- Materiality determined
- —
- Notification sent
- Sep 27, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Reported this incident to law enforcement
- Third party
- via Progress Software Corporation
- Initial access
- supply_chain
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- CA 60-day late · 119d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 31, 2023→ Notified: Sep 27, 2023119d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.