Discovery variance · Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster; needs two dated filings.
State AGConfirmedLifecycle stage 2 of 3: ConfirmedUnverified claimConfirmedEnforcedhigh sensitivity
Affected (total reported)
—
Data types
2
Financial account · Authentication
Jurisdictions
1
MA
Linked filings
4
all State AG
Sensitive data
authentication
Timeline
Earliest sighting first · deep chronology in Litigation Timeline
Breach window
Oct 3, 2025 → May 4, 2026
When the intrusion reportedly occurred, per the linked filings
The Village Bank notified Massachusetts residents of a suspected data compromise involving a third-party merchant's payment card environment. The breach affected debit card data (CVC2, account number, expiration date) between October 2025 and May 2026. The Bank's own systems were not breached. Cardholders were offered free card replacement.
The Village Bank notified Massachusetts residents of a suspected data compromise involving a third-party merchant's payment card environment. The breach affected debit card data (CVC2, account number, expiration) for transactions between July 2025 and March 2026. The Bank's own systems were not breached. Customers were advised to monitor for fraud and offered card replacement.
The Village Bank notified Massachusetts residents of a merchant payment card environment breach affecting transactions between November 1, 2025, and December 31, 2025. The bank's own systems were not breached. Compromised data included debit account numbers, expiration dates, and CVC2 codes. The bank reviewed account activity for fraud and offered card reissuance.
The Village Bank notified Massachusetts residents of a suspected data compromise involving a third-party merchant's payment card environment. The breach affected debit card data (CVC2, account number, expiration) for transactions made between July 1, 2024, and June 30, 2026. The bank stated its own systems were not breached and found no unauthorized transactions, but offered card reissuance.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.