Cadence Bank
ent_019e0db3a07633c78d19a5a15cd65c94
Disclosures
7
State AG · HHS OCR · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
13,862
as filed · HHS OCR MS
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cadence Bank
- Normalized
- cadence bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- Q7C315HKI8VX0SSKBS64
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🐻California State AGas victim2024-01-26
Cadence Bank disclosed a data breach affecting current and former employees of Hall's Culligan, whose insurance was handled by Cadence Insurance (a Cadence Bank subsidiary). An unauthorized third party exploited a zero-day vulnerability in the MOVEit Transfer application (owned by Progress Software) to access and download data between May 28-31, 2023. Cadence Bank learned of the vulnerability on June 1, 2023. Affected data may include names, addresses, dates of birth, medical/treatment information, and health insurance information. Cadence Bank engaged forensic investigators, notified law enforcement, and implemented security enhancements.
- 🍁Vermont State AGas victim2023-11-22
Cadence Bank notified Vermont residents of a data breach involving the MOVEit Transfer application. An unauthorized third party exploited a zero-day vulnerability in Progress Software's MOVEit between May 28-31, 2023, to access and download personal information including names, SSNs, driver's licenses, and financial account data. Cadence engaged forensic investigators, reported to law enforcement, and offered credit monitoring services.
- 🐻California State AGas victim2023-11-22
Cadence Bank notified customers of a data security incident involving a previously unknown vulnerability in the ACH Transfer application owned by Progress Software Corporation. An unauthorized third party exploited this zero-day vulnerability between May 28 and May 31, 2023, accessing and downloading personal information. The bank launched a forensic investigation, contacted law enforcement, and offered identity protection services. Affected data may include name, address, date of birth, SSN, driver's license, passport number, and financial account information.
- MSHHS OCRas victim2023-10-27
Cadence Bank (MS) reported to HHS OCR on 2023-10-27 a Hacking/IT Incident affecting 13,862 individuals. The covered entity reported that its business associate experienced a cyber-attack that compromised PHI stored on a network server. Exposed information included names, addresses, dates of birth, Social Security numbers, driver's license numbers, health insurance information, claims and financial information, and other treatment information. The BA implemented additional technical safeguards and offered complimentary credit monitoring.
- 🐻California State AGas victim2023-09-15
Cadence Bank disclosed a data breach resulting from the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer application. An unauthorized third party accessed and downloaded personal information, including names, addresses, SSNs, and financial account details, between May 28-31, 2023. Cadence learned of the vulnerability on June 1, 2023, and determined the scope of the breach by August 16, 2023. The bank implemented patches, engaged forensic investigators, notified law enforcement, and offered identity protection services to affected individuals.
- 🍁Vermont State AGas victim2023-09-15
Cadence Bank notified Vermont residents of a data breach involving the MOVEit Transfer application by Progress Software. An unauthorized third party exploited a zero-day vulnerability to access and download personal information (names, SSNs, driver's licenses, financial account data) between May 28-31, 2023. Cadence engaged forensic investigators, reported to law enforcement, and offered credit monitoring.
- 🦬Montana State AGas victim2023-09-15
Cadence Bank reported a data breach to the Montana Attorney General. The breach was reported on 2023-09-15. The breach occurred from 5/28/2023 to 5/31/2023. 117 Montana residents were affected.