CENTRAL BANK
ent_019e2413c344a0c2548ca2803cd78815
Disclosures
4
State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
4,747
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CENTRAL BANK
- Normalized
- central bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 254900TG3REX549BAZ53
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🦞Maine State AGas victim2023-12-08
Commercial Finance Corporation, doing business as Central Bank, experienced an unauthorized access incident that affected 792 individuals, including one Maine resident. The breach occurred on July 1, 2022, and was discovered on September 23, 2023. The compromised information included names and Social Security numbers. The company began notifying affected individuals on December 5, 2023, and offered 24 months of identity theft protection services through Experian.
- 🦬Montana State AGas victim2022-03-08
Central Bank reported a data breach to the Montana Attorney General. The breach was reported on 2022-03-08. The breach occurred on 12/27/2021. 1 Montana residents were affected.
- 🦞Maine State AGas victim2022-03-08
Central Bank, a financial services organization, experienced an external system breach on December 27, 2021. The incident, discovered on February 15, 2022, affected 4,747 individuals. The compromised information included names combined with financial account numbers or credit/debit card numbers along with their respective security codes or PINs. Central Bank began notifying affected individuals in writing on March 8, 2022, and offered one year of identity monitoring services through Kroll.
- ⛰️New Hampshire State AGas victim2022-03-08
Central Bank notified the New Hampshire Attorney General of a security incident involving unauthorized access to server files on December 27, 2021. The breach affected 18 New Hampshire residents, exposing names, Social Security numbers, and account numbers. Central Bank contained the incident, engaged outside cybersecurity and law enforcement, and began mailing notifications on March 8, 2022, offering one year of Kroll identity monitoring services.