Arvest Bank reported a cybersecurity incident involving its third-party vendor, Fiserv. Between May 27 and May 31, 2023, a zero-day SQL injection vulnerability in Fiserv's MOVEit Transfer tool was exploited, resulting in the exfiltration of customer data. The breach was discovered on October 13, 2023. A total of 26,388 individuals were affected, including one Maine resident. Arvest Bank notified affected individuals on January 30, 2024, and provided two years of identity theft protection services.
Affected (this filing): 26,388