No Connecticut residents appear to be harmed by the massive data breach on Tuesday which was tied to a piece of third-party software, potentially exposing the personal information of over 95,000 Massachusetts M&T Bank customers.
M&T filed a letter with Massachusetts Attorney General Andrea Campbell’s office stating that customer information such as names, addresses and M&T account numbers may be exposed. The breach occurred on a third-party platform that uses the file transfer software MOVEit.
“As of now, we have not received any breach notices from M&T Bank and so far haven’t received any inquiries or complaints from Connecticut M&T customers,” Richard Funaro, deputy director of communications for the Office of the Connecticut Attorney General, said.
MOVEit is a software owned by Burlington-based Progress Software and used by government agencies, major financial firms and thousands of other organizations. Other organizations that use the MOVEit software, such as UMass Chan Medical School, have also had customer information be potentially compromised.
“M&T’s internal systems were not compromised, and they continue to remain secure. Our investigation determined that limited customer information held by certain third-party service providers was compromised. Specifically, name, address, and M&T account number(s) have been exposed as part of this incident. No PINs or passwords were exposed. This information did not include sensitive data such as social security numbers, date of birth, or debit/credit card numbers. We are now directly informing any customers who may have been affected,” Frank Lentini, M&T Bank senior communications director, said in an email.
The bank said once it learned of the incident, it immediately installed the required security patches and began an investigation to understand the potential exposure of customer data.





