Full Report
A data breach involving Coastal Heritage Bank was reported in May 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Coastal Heritage Bank Data Exposure
## Executive Summary
In May 2026, Coastal Heritage Bank (and its parent company Equitable Bancorp MHC) reported a data breach involving the potential compromise of personal information. While no specific evidence of data misuse has been confirmed, the bank is treating the event as a medium-severity incident. The bank has initiated a response involving customer notification and identity monitoring services.
## Incident Details
- **Discovery Date:** Not disclosed (Reported May 5, 2026)
- **Incident Date:** Unknown/Prior to May 5, 2026
- **Affected Organization:** Coastal Heritage Bank / Equitable Bancorp MHC
- **Sector:** Financial Services / Banking
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Not disclosed.
- **Vector:** Unknown/Unauthorized third-party access.
- **Details:** The report indicates an unauthorized party gained access to systems, though the entry point remains under investigation.
### Lateral Movement
- **Details:** Specific technical details regarding internal movement within the Coastal Heritage Bank or Equitable Bancorp MHC network have not been publicly disclosed.
### Data Exfiltration/Impact
- **Details:** Personal information of an unspecified number of individuals was affected. The specific data fields (e.g., SSNs, account numbers) have not been confirmed in the preliminary report, though the bank is monitoring for identity theft risks.
### Detection & Response
- **Detection:** The incident was identified through internal monitoring or disclosure by the parent company.
- **Response actions taken:** The bank officially reported the breach on May 5, 2026, notified regulatory bodies, and began offering credit monitoring to affected parties.
## Attack Methodology
*Note: Due to limited public disclosure, several technical fields are marked as Unknown.*
- **Initial Access:** Unauthorized third-party access (Vector Unknown)
- **Persistence:** Unknown
- **Privilege Escalation:** Unknown
- **Defense Evasion:** Unknown
- **Credential Access:** Unknown
- **Discovery:** Unknown
- **Lateral Movement:** Unknown
- **Collection:** Gathering of "personal information"
- **Exfiltration:** Exfiltration confirmed via third-party access
- **Impact:** Potential for identity theft and financial fraud
## Impact Assessment
- **Financial:** Potential for unauthorized account access; costs associated with providing 24 months of identity monitoring.
- **Data Breach:** Exposure of personal information for an undisclosed number of customers.
- **Operational:** Disruption for remediation and incident response activities.
- **Reputational:** Medium; poses a risk to customer trust in the bank’s data handling practices.
## Indicators of Compromise
- **Network indicators:** coastalheritagebank[.]com (Affected domain)
- **File indicators:** Not disclosed.
- **Behavioral indicators:** Unauthorized access to databases containing personal identifying information (PII).
## Response Actions
- **Containment measures:** Investigation into the unauthorized third-party access point.
- **Eradication steps:** Not explicitly detailed in the public report.
- **Recovery actions:** Offering 24 months of complimentary identity monitoring via Kroll; advising customers to place credit freezes.
## Lessons Learned
- **Key takeaways:** Financial institutions remain high-value targets for data theft even if immediate financial fraud is not the primary outcome.
- **What could have been done better:** Earlier disclosure of specific data types involved would allow customers to take more targeted protective measures.
## Recommendations
- **Prevention:** Implement phishing-resistant Multi-Factor Authentication (MFA) using hardware keys or authenticator apps.
- **Detection:** Deploy continuous attack surface management (ASM) to identify vulnerabilities in third-party and parent company connections.
- **Customer Protection:** Advise all customers to monitor bank statements and place security freezes on credit reports with major bureaus.