The Bank of Canton
ent_019e616e2d09a01db162c93913e6769b
Disclosures
3
State AG · 3 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
10,070
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The Bank of Canton
- Normalized
- the bank of canton— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300J8Y8IPQFMMIT88
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- ⛰️New Hampshire State AGas victim2023-10-23
Bank of Canton notified the New Hampshire Attorney General of a data security incident involving its third-party service provider's use of Progress Software's MOVEit application. The provider suffered a cybersecurity incident on or around May 27, 2023, exploiting a previously unknown vulnerability. Bank of Canton was notified on August 3, 2023. Approximately 41 New Hampshire residents were affected. Personal information related to deposit accounts was potentially obtained. No evidence of misuse was found. Notifications were mailed on October 20, 2023, offering credit monitoring.
- 🦞Maine State AGas victim2023-10-23
Bank of Canton reported a data breach occurring on May 27, 2023, discovered on September 22, 2023. The incident involved the exploitation of a vulnerability on an FTP platform used by a third-party service provider. Approximately 10,070 individuals were affected, including 31 Maine residents. The breach compromised names and Social Security Numbers. The bank provided written notification and offered 24 months of identity theft protection services via Kroll, Inc.
- 🍁Vermont State AGas victim2023-10-20
Bank of Canton notified Vermont AG of a data breach involving its third-party provider's MOVEit Managed File Transfer application. The incident, occurring around May 27, 2023, exposed customer deposit account names, account numbers, and Social Security numbers. Bank of Canton determined sufficient information to notify customers by September 22, 2023, and offered 24 months of identity monitoring.