1st Source Bank reports about 450,000 records exposed in MOVEit hack
- Organization
- 1st Source Corporation
- Exploit
- Supply Chain Attack
- Industry
- Financial Services
1st Source Corporation, the South Bend, Indiana parent of 1st Source Bank, said in July 2023 that roughly 450,000 records belonging to commercial and individual clients had been exposed after attackers exploited the MOVEit Transfer file transfer software the bank used.
Reuters reported on July 24, 2023 that the lender confirmed the figure and was working to identify and notify the individuals involved. The bank had filed a breach notice with the Maine Attorney General's office on July 14.
According to that filing and subsequent reporting, the exposed information could include names, dates of birth, Social Security numbers, driver's license or state identification card numbers and other government identification numbers. Both client and employee records were said to be affected.
The incident was part of the wider campaign against MOVEit Transfer, in which the Clop extortion group exploited a zero day flaw in the Progress Software product disclosed at the end of May 2023. Hundreds of organizations that ran the software were caught up in it.
1st Source said it brought in cybersecurity specialists to investigate the scope of the compromise and offered all affected individuals a year of complimentary identity and credit monitoring through Kroll.