1st Source Corp says unauthorized third-party gained access to sensitive client data By Investing.com


1st Source Corp (SRCE) says unauthorized third-party gained access to sensitive client data

1st Source Corp (SRCE) disclosed:

On May 31, 2023, a vendor to 1st Source Bank, a wholly owned subsidiary of 1st Source Corporation (the “Company”), Progress Software Corporation (“Vendor”), disclosed a previously unknown vulnerability in its MOVEit file transfer software (“MOVEit”) that could enable malicious actors to gain unauthorized access to sensitive files and information. MOVEit is used by thousands of organizations for secure data file transfers and is now the subject of a widely reported cybersecurity event impacting numerous organizations and governmental agencies around the world. The Company uses MOVEit for secure file transfers supporting internal operations and client services.

Upon learning of the vulnerability, the Company promptly deployed cybersecurity defenses. This included patching the software according to the Vendor’s published protocols, hardening of the host server containing the MOVEit software, and launching an internal investigation in partnership with outside independent cybersecurity forensic experts. The Company’s investigation is ongoing, and it is also in contact with law enforcement and regulatory authorities.

As part of its continuing investigation, the Company discovered that an unauthorized third-party gained access to sensitive client data of commercial and individual clients, including personally identifiable information. The Company has notified and is working with its commercial clients so impacted and is in the process now of identifying and directly notifying individual clients who have been impacted. The Company will ensure that appropriate notifications are provided to impacted individuals who will be offered complimentary credit monitoring and identity restoration services. These will be described in the notifications.
While the investigation is still ongoing, the vulnerability has been contained and there is no indication that there has been any impact on any of the Company’s information systems other than the MOVEit application. There has been no interruption to the Company’s systems, services, or business operations. The Company is aware that certain of its critical vendors may also have been impacted by the same vulnerability, as it believes every user of this version of MOVEit software was, and that the Company’s data processed and/or stored by such vendors may have been impacted. While the Company has not received any notification that this happened, it will assess and respond to any impacts as part of its ongoing investigation or if so notified.

The Company is continuing to evaluate the impact of the vulnerability, including certain remediation expenses and other potential liabilities. The Company does not currently believe the incident will have a material adverse effect on its business, operations, or financial results.



Source link

Skip to content