LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Orrstown Bank Data Breach Notice (Massachusetts Attorney General)

CRITICAL severityConfirmedHow we verify

Orrstown Bank Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 11, 2026
Orrstown Bank Data Breach Notice (Massachusetts Attorney General)

Reported June 11, 2026. Approximately 68 people affected.

CRITICAL
Severity
68
People affected
3
Data types exposed
June 11, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Orrstown Bank has disclosed a data breach affecting 68 Massachusetts residents, exposing their Social Security numbers, financial account numbers, and driver’s license numbers. The notice was filed with the Massachusetts Attorney General on June 11, 2026; anyone who received a notice or believes their information may be involved should review the bank’s guidance and take protective steps.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
68 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Orrstown Bank notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on June 11, 2026. According to that notice, the incident involved personal information belonging to 68 people, and the types of data listed as exposed include Social Security numbers, financial account numbers, and driver’s license numbers.

For those whose records were involved, the combination of identity and account identifiers raises practical risks of fraud and account misuse. Public detail beyond the notice itself remains limited; what follows sticks to what has been disclosed and to general context that helps ordinary readers understand why notices like this matter.

What happened

Orrstown Bank submitted a data breach notice that was reported on June 11, 2026, in connection with the Massachusetts Attorney General’s consumer-protection reporting channel and the Massachusetts Office of Consumer Affairs. The filing indicates that 68 individuals were affected. The notice lists Social Security numbers, financial account numbers, and driver’s license numbers among the information exposed.

The public record reflected in these facts does not describe how the incident was discovered, whether systems were accessed by an unauthorized party, whether data were copied or viewed, or the precise window of exposure. Method, technical root cause, and any broader geographic scope beyond the Massachusetts notification are undisclosed in the material provided. What is established is the organization’s formal notice, the reported headcount of 68 people, and the named categories of data.

How a breach like this happens

Incidents that lead banks and similar institutions to send notices of this kind often follow familiar patterns, though none of these patterns is confirmed for this specific case. Attackers or opportunistic actors may obtain credentials through phishing, reuse of passwords from other breaches, or malware on an employee or vendor device. Once inside a network or application, they may reach customer databases, document stores, or backup systems that hold identity and account fields.

Other common paths include misconfigured cloud storage, compromised third-party software used for lending, payments, or customer service, or physical or logical access to devices that temporarily hold sensitive files. In many cases the organization learns of the event through internal monitoring, a vendor alert, law-enforcement contact, or unusual account activity reported by customers. After containment, institutions typically review what fields were in the affected systems, determine whose records were involved, and issue notices required by state law when certain identifiers—especially Social Security numbers and financial account data—are implicated.

No threat group is attributed in the available facts, and nothing here should be read as a finding about how Orrstown Bank’s systems were or were not compromised. The description above is general background only.

Who is Orrstown Bank?

Orrstown Bank is a banking organization—part of the consumer and commercial financial sector that holds deposits, extends credit, and maintains customer account relationships. Institutions of this type routinely collect and retain information needed to open accounts, verify identity under federal “know your customer” rules, process loans and payments, and meet regulatory record-keeping obligations.

That role makes a breach notice consequential even when the reported number of affected people is relatively small. Banks sit at the intersection of identity verification and money movement. Records they hold can be reused by criminals to impersonate customers, open new credit, or attempt unauthorized transfers. A formal notice to a state attorney general’s office or consumer-affairs office is a standard legal step when an organization concludes that personal information of residents may have been exposed, and it is often how the public first learns that a defined set of people should take protective steps.

What data was at risk

The Massachusetts notice names three categories of information as exposed: Social Security numbers, financial account numbers, and driver’s license numbers. Those are the only data types established by the facts provided. No inventory of additional fields—such as full names, addresses, dates of birth, email addresses, or transaction histories—is confirmed in the disclosed summary, even though banks commonly maintain such information in the ordinary course of business.

Because Social Security numbers and government ID numbers are long-lived identifiers, and because financial account numbers can be used in attempts to access or manipulate accounts, the named categories are among those state breach laws treat as sensitive. Exact contents of any particular file or system, and whether every affected person had all three data types involved, are not detailed beyond the notice’s listing of those categories.

Why it matters

For affected individuals, exposure of Social Security numbers and driver’s license numbers can support identity theft, tax-refund fraud, or the creation of synthetic identities. Financial account numbers can be used in social-engineering calls to banks, attempts to add unauthorized payees, or fraud against linked services. Even when a bank monitors accounts and reissues credentials, the identity data can circulate for years and be reused in unrelated scams.

For the organization, a breach notice carries operational cost—investigation, customer support, possible credit-monitoring offers, and regulatory scrutiny—and can affect customer trust. The reported scale of 68 people is modest compared with some large retail or healthcare incidents, but impact is personal for anyone whose identifiers were involved. Nothing in the public facts establishes negligence or assigns blame; the significance lies in the sensitivity of the data types named and the need for practical follow-up by those notified.

Were you affected?

If you received a letter or email from Orrstown Bank about this incident, treat it as the authoritative source for whether your information was included and for any enrollment instructions the bank provides. If you are a customer or former customer and are unsure, contact the bank through a verified phone number or portal—not through links in unexpected messages—and ask whether you are among those covered by the June 2026 Massachusetts notice.

Practical first steps many people take after notices that list Social Security numbers, financial account numbers, and driver’s license numbers include:

Readers can also run a free exposure scan of their email address to check whether that address has appeared in known breach datasets elsewhere online. That kind of check does not replace the bank’s official notice for this incident, but it can help you see whether your email is already circulating in other dumps and whether you should tighten passwords and enable multi-factor authentication on important accounts.

Public detail on this event is limited to the organization’s notice as reported on June 11, 2026, the figure of 68 people affected, and the named data categories. Anyone who believes they may be included should rely on direct communication from Orrstown Bank and on standard identity-protection steps rather than on incomplete secondary summaries.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyOrrstown Bank security record
52/100
DoxxScan™ · Elevated doxx risk
D+ 56Weak record

1 reported incident on record.

See Orrstown Bank’s full breach history →
RelatedMore incidents at Orrstown Bank

More recent breaches

Murfreesboro Medical Clinic Data Breach Notice (Massachusetts Attorney General)August 27, 2026Spectrum Laboratory Products, Inc. Data Breach Notice (Massachusetts Attorney General)August 27, 2026Healthfirst Bluegrass, Inc. Data Breach Notice (Massachusetts Attorney General)August 27, 2026Alan Gordon, CPA Data Breach Notice (Massachusetts Attorney General)August 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Orrstown Bank Data Breach Notice (Massachusetts Attorney General) →

Source: Massachusetts Office of Consumer Affairs breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram