1st Source Bank
ent_019e20da3239a21eb16944ac9e7e3eeb
Disclosures
17
State AG · HHS OCR · 10 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
450,000
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 1st Source Bank
- Normalized
- 1st source bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- LCUAWMT4M5H8DJ8DFH49
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- 1ST SOURCE CORP— as stated in the breach filing
Disclosure history (17)newest first
- California State AGas victim2023-11-28
1st Source Bank notified customers that their personal information, including names and Social Security numbers, may have been acquired without authorization due to a critical vulnerability in the MOVEit file transfer software provided by Progress Software. The bank became aware of the alert on June 1, 2023, and patched the system. The breach date listed by the CA AG is May 27, 2023. The bank engaged cybersecurity experts and is offering 12 months of identity monitoring via Kroll.
- INDIANAHHS OCRas victim2023-11-20
The business associate (BA), 1st Source Bank, reported that a software application exposed the protected health information (PHI) of 1,477 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses, claims and health insurance information, and financial and other treatment information. In response to the breach, the BA implemented additional administrative, technical, and security safeguards to better protect PHI.
- Indiana State AGas victim2023-09-21
1st Source Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-01 and was reported on 2023-09-21. 344,931 Indiana residents were affected. 450,000 individuals affected in total.
- Oregon State AGas victim2023-07-27
1st Source Bank reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-27. The breach occurred during 6/1/2023 - 6/1/2023. The breach was discovered on 6/1/2023. 446,146 individuals were affected. Notice was sent on 7/25/2023.
- California State AGas victim2023-07-26
1st Source Bank disclosed a data breach involving the MOVEit software vulnerability exploited by an external actor. On June 1, 2023, the bank became aware of the vulnerability alert and patched its systems. Investigation revealed that data including names, Social Security numbers, driver's license numbers, and dates of birth may have been acquired without authorization. The bank engaged cybersecurity experts and offered 12 months of identity monitoring via Kroll.
- New Hampshire State AGas victim2023-07-26
1st Source Bank filed a supplemental notice with the New Hampshire Attorney General regarding a MOVEit vulnerability incident. The bank became aware of the vulnerability on June 1, 2023, and confirmed customer PII was potentially acquired on June 24, 2023. 162 New Hampshire residents were notified. The bank partnered with Kroll to provide identity monitoring services.
- Washington State AGas victim2023-07-20
1st Source Bank notified Washington AG of a supplemental notice for 6 additional residents affected by the MOVEit vulnerability. Total WA residents notified: 777. Incident discovered June 1, 2023; data accessed June 1, 2023. Data included names, SSNs, driver's licenses, DOBs. Initial notifications sent July 2023.
- Oregon State AGas victim2023-07-20
1st Source Bank reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-20. The breach occurred during 6/1/2023 - 6/1/2023. The breach was discovered on 6/1/2023. 436,519 individuals were affected. Notice was sent on 7/14/20237/17/20237/18/20237/19/2023.
- California State AGas victim2023-07-19
1st Source Bank disclosed a data breach affecting customer information due to a vulnerability in the MOVEit file transfer software provided by Progress Software. The bank became aware of the vulnerability alert on June 1, 2023, and determined that data may have been acquired without authorization on June 24, 2023. Affected data includes names, Social Security numbers, driver's license numbers, and dates of birth. The bank patched the system, engaged cybersecurity experts, and offered 12 months of identity monitoring through Kroll.
- Montana State AGas victim2023-07-19
1st Source Bank notified Montana residents of a data breach involving the MOVEit file transfer vulnerability. The bank discovered the vulnerability on June 1, 2023, and patched the system. Affected data included names, SSNs, driver's license numbers, and dates of birth. The bank engaged forensic experts and offered 12 months of credit monitoring via Kroll.
- Massachusetts State AGas victim2023-07-19
1st Source Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-07-19. 623 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-07-19
1st Source Bank reported a ransomware incident that was discovered on June 1, 2023. The breach impacted approximately 450,000 individuals, compromising their names and Social Security numbers. The bank began notifying affected parties on July 14, 2023, and offered 12 months of identity monitoring services through Kroll.
- Indiana State AGas victim2023-07-14
1st Source Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-01 and was reported on 2023-07-14. 351,762 Indiana residents were affected. 450,000 individuals affected in total.
- Vermont State AGas victim2023-07-14
1st Source Bank notified Vermont consumers of a data breach linked to the MOVEit file transfer software vulnerability. The incident, discovered June 1, 2023, potentially exposed names, SSNs, driver's license numbers, and dates of birth. The bank patched its system, engaged forensic experts, and offered 12 months of identity monitoring through Kroll.
- Illinois State AGas victim2023-01-01
1ST SOURCE BANK filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-475). The register records the breach as discovered on May 31, 2023. Additional entities named: MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2008-06-02
1st Source Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-06-02. 101 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2008-06-02
1st Source Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2008-06-02. 111 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- 1st Source Bank’s filing is one of at least 96 in the Progress Software Corporation supply-chain incident (2023).