2024 Western Alliance Bank — Cleo (Cl0p MOVEit) third-party breach notice; ~21.9k consumers in state summaries
Data compromised
Customer PII categories described in breach-notification templates referenced by news coverage
Technical writeup
Regulatory-facing articles tied Western Alliance consumer notifications to Cleo Communications as a MOVEit-era third-party file-transfer compromise disclosed in 2024, with ~21,899 impacted individuals cited in trade summaries of multi-state notice language.
Root cause
Supply-chain exploitation of managed file transfer infrastructure (Cl0p campaign ecosystem)