Merrick Bank
ent_019fcc3491c5ae828131cd73f61213ad
Disclosures
7
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
161
as filed · State AG MT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Merrick Bank
- Normalized
- merrick bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300FGCMJCC78W3068
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- merrickbank.com
Disclosure history (7)newest first
- Montana State AGas victim2023-12-28
Merrick Bank notified Montana residents of a data breach involving MOVEit Transfer vulnerabilities. Unauthorized access occurred between May 27-31, 2023, before the vulnerability was publicly disclosed. Personal information was exfiltrated. The bank launched an investigation, patched systems, and offered two years of complimentary identity monitoring through Kroll.
- California State AGas victim2023-12-28
Merrick Bank notified customers of a data breach involving MOVEit Transfer software. Unauthorized actors exploited a vulnerability in the software between May 27 and May 31, 2023, obtaining files containing personal information. The bank launched an investigation, patched systems, and offered two years of identity monitoring through Kroll.
- Illinois State AGas victim2023-01-01
MERRICK BANK filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-867). The register records the breach as discovered on May 31, 2023. Additional entities named: FIZERV, MOVEIT. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas reporting2021-03-23
Merrick & Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-03-23. 10 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2019-04-12
Merrick Bank notified the NH AG that credential stuffing attacks on its mobile banking app affected 15 NH residents. Unauthorized access occurred using credentials obtained elsewhere. Impacted data included names, emails, account balances, credit limits, last 4 digits of card numbers, and transaction histories. Notification sent April 12, 2019.
- Montana State AGas victim2019-04-12
Merrick Bank notified Montana residents of a data security incident detected on March 8, 2019. Unauthorized individuals accessed some cardholder online accounts using credential information obtained elsewhere. Impacted data included names, emails, account balances, credit limits, last four digits of credit cards, and transaction histories. The bank engaged forensic experts, reported to law enforcement, and offered one year of credit monitoring.
- Massachusetts State AGas victim2019-04-12
Merrick Bank Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-04-12. 49 Massachusetts residents were affected. The report records the breach type as electronic.
Supply-chain cascadesreviewed and confirmed
- Merrick Bank’s filing is one of at least 97 in the Progress Software Corporation supply-chain incident (2023).