BankGloucester
ent_019e232123a5adaa5415ca066c214e7b
Disclosures
6
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
19,283
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BankGloucester
- Normalized
- bankgloucester— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300GS4TO8CL1SR344
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Massachusetts State AGas victim2025-12-17
Bank Gloucester reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-12-17. 16 Massachusetts residents were affected.
- Massachusetts State AGas victim2023-08-22
BankGloucester reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-22. 17,231 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2023-08-22
BankGloucester reported a third-party vendor data breach that affected 138 Maine residents. The breach was discovered on August 16, 2023, and occurred on May 30, 2023. The compromised data included financial account numbers or credit/debit card numbers in combination with security codes, access codes, or PINs. BankGloucester offered two years of credit monitoring and identity theft protection services through Equifax.
- Montana State AGas victim2023-08-22
BankGloucester notified customers that a third-party vendor, Darling Consulting Group, was affected by the MOVEit Transfer vulnerability. The incident potentially exposed customer names, DOBs, SSNs, and account numbers. The bank launched an investigation and offered 2 years of Equifax credit monitoring.
- New Hampshire State AGas victim2023-08-22
BankGloucester notified the NH Attorney General of a security incident affecting 327 NH residents. The breach originated from a third-party vendor, Darling Consulting Group (DCG), which was compromised via the MOVEit Transfer software vulnerability (exploit_vuln) around May 30-31, 2023. BankGloucester detected the incident on July 12, 2023, upon notification from DCG. The investigation concluded on August 16, 2023, confirming the exposure of personal information. Notifications were mailed on August 22, 2023, offering 2 years of Equifax credit monitoring.
- Vermont State AGas victim2023-08-22
BankGloucester notified consumers of a data breach affecting its third-party vendor, Darling Consulting Group, which used Progress Software's MOVEit Transfer. The vulnerability, disclosed May 31, 2023, allowed unauthorized access to data including names, SSNs, DOBs, and account numbers. BankGloucester offered 2 years of Equifax credit monitoring. No evidence of misuse was found.
Supply-chain cascadesreviewed and confirmed
- BankGloucester’s filing is one of at least 6 in the Darling Consulting Group supply-chain incident (2023).