|
Subsequent Events
|9 Months Ended
Sep. 30, 2023
|Subsequent Events [Abstract]
|Subsequent Events
|Subsequent Events
The Company evaluated subsequent events through the date the consolidated financial statements were filed with the SEC and incorporated into the consolidated financial statements the effect of all material known events determined by Accounting Standards Codification ("ASC") 855, Subsequent Events, to be recognizable events. The following item was deemed to be a subsequent event by the Company.
On October 12, 2023, the Bank received email notification from one of its third-party vendors (the "Vendor") that the Vendor used MOVEit Transfer ("MOVEit"), a managed file transfer software developed and maintained by Progress Software Corporation ("PSC"), to transfer information in connection with processing of Bank customer accounts and item processing of Bank customer accounts, including check images, deposit slips, remote deposit capture files, and reports. The Vendor informed the Bank that its review indicates that the affected files included the following data elements for some or all of the affected Bank customers and accounts: name, business name, address, state, telephone number, date of birth, full social security number, tax ID number, account number, and routing number. The Bank estimates that approximately 33% of its customers and approximately 26% of customer accounts are affected by the Vendor incident. The Bank has notified the affected customers in writing about the Vendor incident.
PSC recently disclosed a zero-day vulnerability, a previously unknown flaw, in MOVEit that could enable malicious actors to gain unauthorized access to sensitive files and information. MOVEit is the subject of a widely reported cybersecurity event impacting numerous private organizations and governmental agencies. The Vendor, and not the Bank itself, uses MOVEit, and the Vendor has informed the Bank that it has rectified the vulnerability that allowed the incident to occur.
The Bank, along with numerous other financial institutions, uses the Vendor for certain regulatory compliance and operational support services, including account hosting and transaction processing. The Vendor has notified law enforcement and its regulators about the Vendor incident. The Bank has notified its primary banking regulators about the Vendor incident, and will continue to keep them informed.
The Company has incurred certain expenses relating to the Vendor incident, and may incur additional expenses. While the Company continues to evaluate the full scope and impact of the Vendor incident, the Company does not currently believe the Vendor incident will have a material adverse effect on the Bank's business and operations or the Company's consolidated financial statements.
|X
- References
+ Details
No definition available.
|X
- Definition
+ References
The entire disclosure for significant events or transactions that occurred after the balance sheet date through the date the financial statements were issued or the date the financial statements were available to be issued. Examples include: the sale of a capital stock issue, purchase of a business, settlement of litigation, catastrophic loss, significant foreign exchange rate changes, loans to insiders or affiliates, and transactions not in the ordinary course of business.
+ Details
Reference 1: http://www.xbrl.org/2003/role/disclosureRef