Sound Community Bank
ent_019e24122e82d135fded8ea22a1d7245
Disclosures
4
State AG · SEC 8-K · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
16,000
as filed · SEC 8-K FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sound Community Bank
- Normalized
- sound community bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300U8DCOOTG96YM89
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🦬Montana State AGas victim2025-11-19
Sound Community Bank reported a data breach to the Montana Attorney General. The breach was reported on 2025-11-19. The breach occurred on 08/14/2025. 11 Montana residents were affected.
- 🌲Washington State AGas victim2025-11-19
Sound Community Bank, a finance sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2025-08-14 and filed notice on 2025-11-19. 5,503 Washington residents were affected. 97 days elapsed between awareness and notification. 0 days to contain the breach.
- 🦞Maine State AGas victim2023-07-17
Sound Community Bank, a financial services organization, reported an external system breach (hacking) that occurred between April 3, 2023, and May 31, 2023. The breach was discovered on June 13, 2023, and affected 3 Maine residents. The compromised information included names and Social Security numbers. Affected individuals were notified on July 18, 2023, and offered 24 months of identity theft protection services through OnAlert Essential Bundle from ChexSystems. The notification was submitted by outside counsel to Fidelity National Information Services, Inc., indicating a third-party vendor was involved.
- FEDERALSEC 8-Kas victim2023-07-14
Sound Financial Bancorp disclosed that its subsidiary Sound Community Bank was affected by the MOVEit Transfer zero-day vulnerability (Progress Software) via a third-party vendor providing account hosting and transaction processing. The vendor used MOVEit to transfer data on approximately 16,000 of the Bank's mobile and online banking customers. Vendor forensics indicate the data was downloaded once during a valid transfer; investigation ongoing. Law enforcement and banking regulators notified.