Northfield Bank
ent_019e6189f9f897512e3a25c2ec0ad46c
Disclosures
7
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
10,106
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Northfield Bank
- Normalized
- northfield bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300BN4MNW5KE16X83
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- New Hampshire State AGas victim2023-10-02
Northfield Bank filed a supplemental notice with the New Hampshire Attorney General regarding a data security event involving a third-party vendor's use of MOVEit Transfer software. The incident occurred between May 27 and May 31, 2023. The bank notified 2 New Hampshire residents. Affected data included personal information potentially including SSNs and government IDs. The bank provided credit monitoring via Kroll and engaged cybersecurity specialists.
- Indiana State AGas victim2023-09-25
Northfield Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-07 and was reported on 2023-09-25. 1 Indiana residents were affected. 10,106 individuals affected in total.
- Vermont State AGas victim2023-09-25
Northfield Bank notified Vermont consumers of a data security event involving its third-party vendor, Progress Software Corporation. The incident, occurring May 27-31, 2023, exploited vulnerabilities in the MOVEit Transfer application. Affected data included names, account numbers, SSNs, and online banking usernames. No passwords were compromised. Northfield Bank engaged cybersecurity specialists and the vendor patched systems. Affected individuals received two years of complimentary identity monitoring through Kroll.
- Massachusetts State AGas victim2023-09-08
Northfield Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-09-08. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-09-08
Northfield Bank notified New Hampshire residents of a data security event involving a third-party vendor's use of MOVEit Transfer software. The incident occurred between May 27 and May 31, 2023, and the bank was notified on August 4, 2023. The breach potentially exposed customer personal information, including government identifiers, via vulnerabilities in the vendor's file transfer application. Northfield Bank engaged cybersecurity specialists and provided credit monitoring services through Kroll to affected individuals.
- Vermont State AGas victim2023-09-08
Northfield Bank notified consumers of a data security event involving its third-party vendor, Progress Software Corporation. The incident, occurring May 27-31, 2023, exploited vulnerabilities in the MOVEit Transfer application. Affected data included names, account numbers, SSNs, and online banking usernames. No passwords were compromised. Northfield Bank engaged cybersecurity specialists and the vendor patched systems. Affected individuals received two years of complimentary identity monitoring via Kroll.
- Maine State AGas victim2023-09-07
Northfield Bank reported a data breach affecting 4,112 individuals due to a security event involving the MOVEit Transfer application at a third-party vendor. The breach occurred between May 27, 2023, and May 31, 2023, and was discovered on August 8, 2023. The compromised information includes names and Social Security numbers. The bank offered affected individuals two years of credit monitoring and identity restoration services.
Supply-chain cascadesreviewed and confirmed
- Northfield Bank’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).