The Bank of Oak Ridge suffered a data breach between April 26 and April 27, 2021, caused by an external system hacking incident. The breach exposed sensitive personal information of 19,865 individuals, including 7 Maine residents, compromising customer names, Social Security numbers, and driver’s license numbers. Such data exposure significantly increases the risk of identity theft and financial fraud for the affected individuals. The bank responded by issuing written notifications to victims on July 7, 2021, and offered one year of identity theft protection services through Kroll to mitigate potential harm. The breach highlights vulnerabilities in the bank’s external systems, raising concerns about cybersecurity measures and the protection of customer data. The leaked information, particularly Social Security and driver’s license numbers, can be exploited for long-term fraudulent activities, posing serious financial and reputational risks to both the bank and its customers.
TPRM report: https://www.rankiteo.com/company/the-bank-of-oak-ridge
"id": "the020090625",
"linkid": "the-bank-of-oak-ridge",
"type": "Breach",
"date": "4/2021",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 19865,
'industry': 'Banking',
'name': 'Bank of Oak Ridge',
'type': 'Financial Institution'}],
'attack_vector': 'External System Breach (Hacking)',
'customer_advisories': 'Identity theft protection services (Kroll) offered '
'for one year',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': 19865,
'personally_identifiable_information': ['Names',
'Social Security '
'Numbers',
"Driver's License "
'Numbers'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)']},
'date_publicly_disclosed': '2021-07-07',
'description': 'The Maine Office of the Attorney General reported that Bank '
'of Oak Ridge experienced a data breach due to an external '
'system breach (hacking) between April 26 and April 27, 2021. '
'The breach impacted 19,865 individuals, including 7 Maine '
'residents, involving customer names, Social Security numbers, '
"and driver's license numbers. Written notification was "
'provided on July 7, 2021, and identity theft protection '
'services through Kroll were offered for one year.',
'impact': {'data_compromised': ['Customer Names',
'Social Security Numbers',
"Driver's License Numbers"],
'identity_theft_risk': 'High (PII exposed)'},
'references': [{'source': 'Maine Office of the Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': ['Maine Office of the '
'Attorney General']},
'response': {'communication_strategy': 'Written notification to affected '
'individuals (July 7, 2021)',
'third_party_assistance': ['Kroll (Identity Theft Protection '
'Services)']},
'title': 'Bank of Oak Ridge Data Breach (April 2021)',
'type': 'Data Breach'}