Breach taxonomy
Summary
On February 6, 2024, SouthState Bank detected a cybersecurity incident and immediately activated its incident response and business continuity protocols. The company proactively isolated parts of its network to contain the unauthorized activity, causing some disruption to business processes. Banking operations continued throughout the incident in all material respects. A cybersecurity firm was engaged and banking regulators and law enforcement were notified. As of the filing date, no material impact on operations had been determined.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to any specific threat actor or category → UNKNOWN.
MethodsSystem Outage
Filing states unauthorized activity was detected and parts of the network were proactively isolated resulting in disruption; no specific attack method (ransomware, exfiltration, etc.) is disclosed.
AssetsRevenue Process
Filing describes disruption to the bank's business processes due to network isolation, affecting revenue-generating banking operations.
EffectsBiz Interruption
Filing states network isolation resulted in some disruption to business processes, qualifying as business interruption, though operations continued in all material respects.
Business continuityEffective
Filing states the company initiated its incident response and business continuity protocols and that operations continued throughout in all material respects → Effective.
Impact
Cybersecurity incident at a regional bank caused some network disruption but banking operations continued in all material respects with no material financial impact disclosed.
InsuranceNot disclosed
Filing makes no mention of insurance.
Read the original SEC filing excerpt
Item 1.05. Material Cybersecurity Incidents. SouthState Bank, N.A., (the Company) detected what was determined to be a cybersecurity incident on February 6, 2024. Upon detection, the Company initiated its incident response and business continuity protocols and began taking measures to disrupt the unauthorized activity. As part of its process to address the incident, the Company proactively took measures to isolate parts of its network, which resulted in some disruption to the Company's business processes. The Company's operations have continued throughout this process in all material respects. The Company is conducting a thorough investigation and a cybersecurity firm has been engaged. Banking regulators and law enforcement have been notified. While the investigation is ongoing, as of the date of this filing, the incident has not had a material impact on the Company's operations, and the Company has not determined the incident is reasonably likely to materially impact the Company's financial conditions or results of operations.