CSIDB logo
Incident

Triad Business Bank

Incident posture

Attack window
Jan 2023
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-14 00:00

Linked entities

Victim
Triad Business Bank
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Triad Business Bank experienced a cybersecurity incident involving unauthorized access to an employee's email account, compromising sensitive consumer information including names and Social Security numbers. The breach impacted over 8,000 individuals, with the bank detecting suspicious activity and securing email accounts before initiating an investigation with cybersecurity specialists. Following confirmation that confidential data within the affected account was exposed, the institution reviewed compromised files to identify impacted parties and subsequently issued notification letters to affected consumers regarding the exposure of their personal information.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 27, 2023, Triad Business Bank detected suspicious activity involving an employee's email account, prompting immediate containment measures that included securing all other user email accounts. The bank initiated an investigation with cybersecurity specialists, which confirmed unauthorized access to the compromised email account between January 24 and January 27, 2023. Forensic analysis revealed that emails and attachments within the breached account contained confidential consumer information. Subsequent review of affected files determined that the compromised data included names and Social Security numbers belonging to at least 8,235 individuals. The bank completed its assessment of the breach scope and impacted consumers before issuing notifications.

Triad Business Bank formally reported the incident to the Office of the Maine Attorney General on May 3, 2023, concurrently dispatching data breach notification letters to all affected individuals. The breach exposed Social Security numbers, creating potential fraud risks for victims given the sensitivity of this identifier. As a financial institution handling personal and business accounts across three North Carolina locations, the incident implicated consumer data entrusted during routine banking operations. No systems beyond the single employee email account were confirmed compromised in the disclosure. The organization's public filing emphasized containment through account security measures but did not specify technical causes or attacker origins. Annual revenue and employee count figures contextualized the scale of the Greensboro-based bank at the time of the breach.

Sources

Sources available to members: 1 source.

CSIDB