
Mississippi-based financial services company Cadence Bank said it suffered a data breach as a result of the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer web application.Founded in 1876, Cadence Bank presently serves the people and communities of Tupelo, Mississippi. The bank offers its customers a wide range of services and operates over 350 branches throughout the southern United States.In a recent filing with the Office of the Attorney General of Montana, Cadence Bank said that it used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application to access its users’ data.On June 1, the bank became aware of a global security incident where the notorious Clop ransomware group exploited a previously unknown vulnerability within MOVEit transfer application. The security incident involving the software victimised the bank and enabled the threat actors to gain access to a database that stored information related to its customers.The bank immediately installed all the patches released by Progress Software to remediate the incident and launched an internal investigation to understand the scope of the incident and determine the nature of the data accessed by the threat actors. Also, Cadence reported the incident to relevant law enforcement authorities.Cadence’s internal investigation confirmed that threat actors were able to access confidential information stored within the MOVEit environment. The compromised data included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, and financial account information.The bank has confirmed that the data breach has only affected servers that hosted the MOVEit application. No other bank’s systems were compromised in the security incident.Earlier this month, Pikeville, Kentucky-based Community Trust Bank suffered a data breach as a result of the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer web application.In a filing with the Office of the Maine Attorney General, the bank said that one of its service providers used Progress Software’s MOVEit Transfer web application to send and receive files securely and was impacted after cyber criminals exploited a zero-day vulnerability in the application to access its users’ data.The global security incident involving the software victimised the bank’s service provider and enabled the threat actors to gain access to a database that stored information related to its customers.Community Trust Bank revealed in its regulatory filing that at least 99,389 individuals were impacted by the cyber security incident. The compromised information included names and other personal identifiers, financial account numbers, credit and debit card numbers along with the security codes, access codes, passwords or PIN for the account.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543