Clustered 4 filings across 3 jurisdictions · filing window Aug 30, 2022 → Nov 1, 2022. View entity profile → Other incidents for this victim →
incident inc_9b1c4375a15b44a7 · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Government ID
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
DE ME NH
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
May 26, 2022
When the intrusion reportedly occurred, per the linked filings
Jul 5, 2022
Reported by DELAWARE AG, NEW HAMPSHIRE AG filings
Aug 25, 2022
Reported by MAINE AG filing
Arvest Bank notified the NH AG of a third-party vendor breach involving Overby-Seawell Company (OSC). Unauthorized access to OSC servers began May 26, 2022. OSC discovered suspicious activity July 5, 2022. Customer data (names, loan info, addresses, insurance policy info) was exposed. 2 NH residents affected. Arvest offered 1-year IDProtect monitoring and credit freeze guidance. Investigation ongoing.
Affected (this filing): 2
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Overby-Seawell Company (OSC), a property insurance validation vendor, notified affected individuals of a data breach involving unauthorized access to OSC servers. Unauthorized access began on May 26, 2022, and was discovered on July 5, 2022. Stolen data included names, SSNs, loan details, and insurance information. OSC engaged forensic specialists, reported to law enforcement, and offered 24 months of credit monitoring. Fulton Bank systems were not impacted.
Fulton Bank notified the New Hampshire Attorney General of a cybersecurity incident involving third-party vendor Overby-Seawell Company (OSC). OSC experienced unauthorized access to its servers beginning May 26, 2022, and discovered suspicious activity on July 5, 2022. The breach compromised customer data including names, SSNs, and loan details for 12 New Hampshire residents. OSC notified Fulton Bank on August 11, 2022, and began mailing notifications on August 30, 2022, offering 24 months of credit monitoring.
Affected (this filing): 12
Overby-Seawell Company, a financial services firm, experienced an external system breach (hacking) that occurred between May 26, 2022, and July 5, 2022. The breach was discovered on August 25, 2022, and affected 111,663 individuals. The compromised information included names and Social Security numbers. In response, the company provided written notifications to affected individuals starting on August 30, 2022, and offered 24 months of identity theft protection services through IDX.
Affected (this filing): 111,663