Pacific Premier Bancorp customer data stolen in vendor's MOVEit breach

Organization
Pacific Premier Bancorp
Exploit
Supply Chain Attack
Industry
Financial Services

Pacific Premier Bancorp, the Irvine, California parent of Pacific Premier Bank, said a vendor it uses for tax and compliance support had been breached through the MOVEit Transfer file sharing software.

In a Form 8-K filed on July 25, 2023, the bank said it had been notified that an unauthorized party obtained bank client data files held by the vendor. Those files contained names, Social Security numbers, account numbers and other personally identifiable information. Pacific Premier said there was no indication its own network or IT systems were involved and no material interruption to its operations.

The bank did not say how many customers were affected, noting that the investigation was continuing. It said it was working with the vendor to notify potentially affected parties and to make the reports required by federal and state law.

The incident was one of hundreds tied to a zero day vulnerability in Progress Software's MOVEit Transfer product, which the Clop extortion group exploited at scale beginning in late May 2023.

American Banker later reported that the Pacific Premier exposure came through Sovos, a tax compliance technology provider, and that the bank went further than most, advising all of its clients to watch for identity theft and fraud rather than only those confirmed as affected.

Sources