Sunflower Bank, National Association
ent_019ea521a75fea4f6d352d2521eba3a2
Disclosures
8
State AG · SEC 8-K · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
132
as filed · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Sunflower Bank, National Association
- Normalized
- sunflower bank national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 2549008TT6UNYR7AXF54
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- FIRSTSUN CAPITAL BANCORP— per SEC Exhibit 21 filing
Disclosure history (8)newest first
- California State AGas victim2023-10-04
Sunflower Bank, N.A. notified customers of a security incident involving a vulnerability in Progress Software's MOVEit file transfer software. The bank was notified of the vulnerability on May 31, 2023. The incident potentially exposed first and last names and financial transaction information. The bank engaged forensic experts, applied patches, and offered credit monitoring.
- New Hampshire State AGas victim2023-10-02
Sunflower Bank, N.A. filed a supplemental data security incident notice with the New Hampshire Attorney General regarding a MOVEit zero-day vulnerability exploit. The bank notified 23 New Hampshire residents starting August 14, 2023. The incident involved unauthorized access via a third-party software vulnerability, resulting in the exfiltration of customer data. The bank is offering credit monitoring services to affected individuals.
- Massachusetts State AGas victim2023-08-22
Sunflower Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-22. 75 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2023-08-15
Sunflower Bank, N.A. was notified on or about May 31, 2023 by Progress Software Corporation of a vulnerability in MOVEit file transfer software, which the bank used for secure file transfers. The bank's MOVEit server was segmented from core systems. Potentially impacted data included names, and financial transaction-related information. The bank engaged outside experts, applied all available fixes, and offered affected individuals Experian credit monitoring.
- Montana State AGas victim2023-08-15
Sunflower Bank, N.A. notified customers of a security incident involving a vulnerability in Progress Software's MOVEit file transfer software. The bank was notified on May 31, 2023. Potentially impacted data includes names and financial transaction information. The bank engaged forensic experts, applied patches, and reported to law enforcement. Affected individuals are offered credit monitoring and identity theft insurance.
- New Hampshire State AGas victim2023-08-15
Sunflower Bank, N.A. notified the NH AG of a data incident involving the MOVEit software zero-day vulnerability. The bank received notice from vendor Progress Software on May 31, 2023. An unauthorized party likely downloaded files from the bank's segmented MOVEit server. 23 New Hampshire residents were affected. The bank engaged forensic experts, applied vendor fixes, and mailed notices offering credit monitoring.
- Indiana State AGas victim2023-08-14
Sunflower Bank, N.A reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-27 and was reported on 2023-08-14. 132 Indiana residents were affected.
- FEDERALSEC 8-Kas victim2023-07-14
FirstSun Capital Bancorp reported that its subsidiary, Sunflower Bank, N.A., was impacted by a zero-day vulnerability in Progress Software's MOVEit file transfer software. An unauthorized party likely downloaded files containing PII from the MOVEit server. The bank engaged forensic experts and applied vendor patches. The investigation is ongoing, and the Bank reported no material interruption to its business operations.
Supply-chain cascadesreviewed and confirmed
- Sunflower Bank, National Association’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).