A bank holding company disclosed in its 2023 10-K Item 1C that customer data was potentially included in the global MOVEit Transfer (Progress Software) incident. The compromise affected a third-party financial-institution vendor, not the Bank's own network. Online/mobile banking customers' personal information may have been copied. The vendor applied Progress's recommended patches; the Bank notified affected customers. Cyber insurance is expected to cover many related costs. Described as the only cybersecurity incident that materially affected the Corporation in FY2023.