1st Source Bank
ent_019e20da3239a21eb16944ac9e7e3eeb
Disclosures
13
SEC 10-K Item 1C · State AG · HHS OCR · SEC 8-K · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
450,000
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- 1st Source Bank
- Normalized
- 1st source bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- LCUAWMT4M5H8DJ8DFH49
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- FEDERALSEC 10-K Item 1Cas reporting2026-02-17
1st Source Corporation (SEC registrant) discloses in its 10-K Item 1C that it has not encountered any cybersecurity incident that has materially impaired or is reasonably likely to materially impair its business, operations, or financial condition. The filing details its cybersecurity governance, risk management framework (CRI Profile/NIST), and controls, but reports no actual breach.
- 🐻California State AGas victim2023-11-28
1st Source Bank notified customers that their personal information, including names and Social Security numbers, may have been acquired without authorization due to a critical vulnerability in the MOVEit file transfer software provided by Progress Software. The bank became aware of the alert on June 1, 2023, and patched the system. The breach date listed by the CA AG is May 27, 2023. The bank engaged cybersecurity experts and is offering 12 months of identity monitoring via Kroll.
- FEDERALHHS OCRas victim2023-11-20
The business associate (BA), 1st Source Bank, reported that a software application exposed the protected health information (PHI) of 1,477 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses, claims and health insurance information, and financial and other treatment information. In response to the breach, the BA implemented additional administrative, technical, and security safeguards to better protect PHI.
- 🦫Oregon State AGas victim2023-07-27
1st Source Bank reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-27. The breach occurred during 6/1/2023 - 6/1/2023. The breach was discovered on 6/1/2023. 446,146 individuals were affected. Notice was sent on 7/25/2023.
- 🐻California State AGas victim2023-07-26
1st Source Bank disclosed a data breach involving the MOVEit software vulnerability exploited by an external actor. On June 1, 2023, the bank became aware of the vulnerability alert and patched its systems. Investigation revealed that data including names, Social Security numbers, driver's license numbers, and dates of birth may have been acquired without authorization. The bank engaged cybersecurity experts and offered 12 months of identity monitoring via Kroll.
- ⛰️New Hampshire State AGas victim2023-07-26
1st Source Bank filed a supplemental notice with the New Hampshire Attorney General regarding a MOVEit vulnerability incident. The bank became aware of the vulnerability on June 1, 2023, and confirmed customer PII was potentially acquired on June 24, 2023. 162 New Hampshire residents were notified. The bank partnered with Kroll to provide identity monitoring services.
- 🌲Washington State AGas victim2023-07-20
1st Source Bank, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2023-06-01 and filed notice on 2023-07-20. 777 Washington residents were affected. 49 days elapsed between awareness and notification. 0 days to identify the breach. 0 days to contain the breach.
- 🦫Oregon State AGas victim2023-07-20
1st Source Bank reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-20. The breach occurred during 6/1/2023 - 6/1/2023. The breach was discovered on 6/1/2023. 436,519 individuals were affected. Notice was sent on 7/14/20237/17/20237/18/20237/19/2023.
- 🐻California State AGas victim2023-07-19
1st Source Bank disclosed a data breach affecting customer information due to a vulnerability in the MOVEit file transfer software provided by Progress Software. The bank became aware of the vulnerability alert on June 1, 2023, and determined that data may have been acquired without authorization on June 24, 2023. Affected data includes names, Social Security numbers, driver's license numbers, and dates of birth. The bank patched the system, engaged cybersecurity experts, and offered 12 months of identity monitoring through Kroll.
- 🦬Montana State AGas victim2023-07-19
1st Source Bank reported a data breach to the Montana Attorney General. The breach was reported on 2023-07-19. The breach occurred on 6/1/2023. 187 Montana residents were affected.
- 🦞Maine State AGas victim2023-07-19
1st Source Bank reported a ransomware incident that was discovered on June 1, 2023. The breach impacted approximately 450,000 individuals, compromising their names and Social Security numbers. The bank began notifying affected parties on July 14, 2023, and offered 12 months of identity monitoring services through Kroll.
- 🍁Vermont State AGas victim2023-07-14
1st Source Bank notified Vermont consumers of a data breach linked to the MOVEit file transfer software vulnerability. The incident, discovered June 1, 2023, potentially exposed names, SSNs, driver's license numbers, and dates of birth. The bank patched its system, engaged forensic experts, and offered 12 months of identity monitoring through Kroll.
- FEDERALSEC 8-Kas victim2023-07-10
1st Source Bank, a subsidiary of 1st Source Corp, disclosed a cybersecurity incident stemming from a vulnerability in Progress Software's MOVEit file transfer software. An unauthorized third party gained access to sensitive client data, including PII. The company patched the software, engaged forensic experts, and is notifying affected clients, offering credit monitoring. The investigation is ongoing.