Arvest Bank
ent_019e20768cc4578d6745fa3989bff89e
Disclosures
10
State AG · 5 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
26,388
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Arvest Bank
- Normalized
- arvest bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- COINQMNIM6RBU631DD85
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Indiana State AGas victim2025-05-30
Arvest Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-08 and was reported on 2025-05-30. 1 Indiana residents were affected. 2,835 individuals affected in total.
- Nebraska State AGas victim2025-05-30
Arvest Bank notified Nebraska residents of a data incident where a customer's debit card information was accidentally attached to an email sent to another customer. The bank acted quickly to have the email deleted and provided one year of free credit monitoring and identity theft recovery to affected individuals. No specific count of affected individuals was disclosed in this notice.
- Maine State AGas victim2025-05-12
Arvest Bank disclosed a data breach occurring on April 24, 2025, where a technical issue during routine system updates temporarily allowed customers to view other customers' account information. The incident affected 7,737 individuals nationwide, including 4 in Maine. Compromised data included names, account numbers, balances, and activity. Arvest Bank resolved the issue by April 25, 2025, and offered 12 months of credit monitoring and identity theft recovery services to affected customers.
- Indiana State AGas victim2025-05-09
Arvest Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-24 and was reported on 2025-05-09. 9 Indiana residents were affected. 7,537 individuals affected in total.
- Nebraska State AGas victim2025-05-09
Arvest Bank experienced a technical error during system updates on April 24, 2025, which temporarily allowed customer accounts to be viewable by other customers during online banking. The incident involved the disclosure of customer names, account numbers, balances, and activity. Arvest Bank restored services by April 25, 2025, and is offering one year of complimentary credit monitoring and identity theft recovery services to affected customers.
- Maine State AGas victim2024-02-01
Arvest Bank reported a cybersecurity incident involving its third-party vendor, Fiserv. Between May 27 and May 31, 2023, a zero-day SQL injection vulnerability in Fiserv's MOVEit Transfer tool was exploited, resulting in the exfiltration of customer data. The breach was discovered on October 13, 2023. A total of 26,388 individuals were affected, including one Maine resident. Arvest Bank notified affected individuals on January 30, 2024, and provided two years of identity theft protection services.
- Maine State AGas victim2022-11-01
Arvest Bank reported a data breach caused by an internal issue at a third-party vendor. The breach occurred on May 26, 2022, and was discovered on July 11, 2022. The incident affected 2 Maine residents, who were notified on October 31, 2022. Arvest Bank offered one year of identity theft protection services to the individuals affected.
- New Hampshire State AGas victim2022-11-01
Arvest Bank notified the NH AG of a third-party vendor breach involving Overby-Seawell Company (OSC). Unauthorized access to OSC servers began May 26, 2022. OSC discovered suspicious activity July 5, 2022. Customer data (names, loan info, addresses, insurance policy info) was exposed. 2 NH residents affected. Arvest offered 1-year IDProtect monitoring and credit freeze guidance. Investigation ongoing.
- Montana State AGas victim2022-10-31
Arvest Bank notified customers of a data breach involving its vendor, Overby-Seawall Company (OSC). An unauthorized party gained access to OSC systems, exposing customer names, loan amounts, loan numbers, mailing addresses, and insurance policy information. Arvest mandated security enhancements and password resets for OSC users and offered one year of complimentary IDProtect identity theft services. No identity fraud was reported at the time of notice.
- Indiana State AGas victim2022-10-31
Arvest Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2022-05-26 and was reported on 2022-10-31. 2 Indiana residents were affected. 7,700 individuals affected in total.
Supply-chain cascadesreviewed and confirmed
- Arvest Bank’s filing is one of at least 10 in the FISERV, INC. supply-chain incident (2023).