Umpqua Bank
ent_7724220876be6cfb41198cb0
Disclosures
6
State AG · SEC 8-K · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
429,252
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Umpqua Bank
- Normalized
- umpqua bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- Columbia Banking System, Inc.— as stated in the breach filing
Disclosure history (6)newest first
- New Hampshire State AGas victim2023-08-18
Umpqua Bank, via vendor FIS, notified New Hampshire AG of a MOVEit Transfer zero-day exploit (T1190) affecting 50 state residents. Personal info (SSN, name) was accessed. FIS patched the system and notified law enforcement. Umpqua offered 24 months of credit monitoring.
- Indiana State AGas victim2023-08-11
Umpqua Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-27 and was reported on 2023-08-11. 143 Indiana residents were affected. 429,252 individuals affected in total.
- California State AGas victim2023-08-11
Umpqua Bank notified California residents that their names and Social Security numbers were accessed due to a third-party vendor's exposure in the global MOVEit Transfer cybersecurity incident. The vendor uses Progress Software's MOVEit Transfer tool, which had a previously unknown vulnerability reported on May 31, 2023. The breach date is listed as May 27, 2023. Umpqua was notified by the vendor on June 21, 2023. No banking information was involved. The bank is offering 24 months of identity monitoring.
- Maine State AGas victim2023-08-11
Umpqua Bank reported a data breach affecting 84 Maine residents, which occurred between May 27 and May 31, 2023. The breach was discovered on June 21, 2023, and was caused by an external system breach (hacking) of a third-party vendor, Fidelity National Information Services, Inc. The compromised information included names and Social Security numbers. Umpqua Bank began notifying affected individuals on August 11, 2023, and offered 24 months of identity monitoring and theft protection services through OnAlert Essential Bundle from ChexSystems.
- Washington State AGas victim2023-08-11
Umpqua Bank, a client of FIS, experienced a data breach via a zero-day vulnerability in Progress Software's MOVEit Transfer tool. The incident exposed names and SSNs of 145,274 Washington residents. FIS disabled the tool, patched systems, and engaged forensic experts. Umpqua notified affected individuals and offered 24 months of credit monitoring.
- FEDERALSEC 8-Kas victim2023-06-27
Columbia Banking System, Inc. disclosed that its subsidiary, Umpqua Bank, was affected by a security incident involving a third-party technology service provider's MOVEit filesharing software. The incident resulted in the unauthorized acquisition of names and Social Security numbers or tax identification numbers of certain consumer and small business customers. Umpqua Bank notified affected customers via email on June 22, 2023. A separate on-premise MOVEit incident was also contained with no data loss. The Company does not currently believe the incidents will have a material adverse effect.
Supply-chain cascadesreviewed and confirmed
- Umpqua Bank’s filing is one of at least 96 in the Progress Software Corporation supply-chain incident (2023).