Were you recently affected by a data breach?

Orange Bank & Trust Company Data Breach

Orange Bank & Trust Company notified customers that their personal information was exposed after unauthorized actors accessed files held by a third-party accounting vendor, Mercadien P.C.

Orange Bank & Trust Company
Date of Breach: September 17, 2025 to October 8, 2025
CAU logo

Who was affected:

Clients of Orange Bank & Trust Company

Impacted Data:

Full name and additional personal information contained in files transferred through a third-party vendor’s file transfer platform

Orange Bank & Trust Company (OB&T) has notified customers that their personal information may have been exposed as a result of a data security incident affecting Mercadien, P.C. CPAs, a third-party accounting and advisory firm the bank uses to support certain services. Companies that share customer data with outside vendors remain responsible for making sure that data stays protected, even when the exposure happens on a third party’s systems rather than their own.

Orange Bank & Trust Company’s Data Breach Investigation

According to a notification letter filed with the Massachusetts Attorney General’s Office, the incident involved Box.com, a third-party managed file transfer platform Mercadien uses to support the services it provides to OB&T and related institutions. Mercadien determined that unauthorized activity occurred within its Box.com environment between September 17, 2025, and October 8, 2025, during which unauthorized actors obtained vendor files that had been transferred through the platform. Those files reportedly included OB&T customer information. OB&T states that the incident did not involve any of its own internal systems and did not affect its ability to service customers. After a review of the affected files, OB&T determined on August 28, 2026, that one or more of the files may have contained an affected customer’s full name along with additional personal information. In response, Mercadien reported taking steps including resetting credentials, replacing firewall devices, and engaging third-party security experts, while OB&T is offering affected individuals complimentary access to Experian IdentityWorks credit monitoring.

Vendor-related data incidents like this one are an increasingly common source of exposure for financial institutions and their customers. Banks routinely share customer records with outside accounting, payroll, and processing vendors to support day-to-day operations, and each of those vendor relationships represents another potential point of failure outside the bank’s own direct control. When a vendor’s file-transfer or cloud storage platform is compromised, the exposure can affect customers of multiple client institutions at once, and the resulting investigation and notification timeline is often longer than a breach confined to a single company’s own systems, since the affected institution must first be notified by the vendor before it can assess and notify its own customers.

The letter notes that OB&T has no current evidence that the exposed information has been used for identity theft or financial fraud, but exposure of a customer’s full name in combination with other personal information taken from a financial institution’s records can still create longer-term fraud risk, particularly if the exposed files included any account or identifying details beyond a name. OB&T’s notice also discloses that 8 Rhode Island residents were affected by this incident; multi-state breach notices commonly report state-specific counts like this rather than a single nationwide total, since notification requirements vary state by state.

When Did This Breach Occur?

Mercadien determined that the unauthorized activity in its Box.com environment took place between September 17, 2025, and October 8, 2025. OB&T completed its review of the affected data and confirmed the impact to specific customers on August 28, 2026, and filed its notification with the Massachusetts Attorney General’s Office in September 2026.

What Information Was Breached?

Per OB&T’s notice, the review determined that one or more of the affected files may have contained the customer’s full name along with additional personal information contained in the vendor’s records. OB&T has not publicly detailed the full universal list of data types beyond name for every affected individual.

What You Can Do

If you received a notification letter from Orange Bank & Trust Company, consider taking the following steps to protect yourself:

  • Enroll in the complimentary Experian IdentityWorks credit monitoring referenced in your notification letter before the enrollment deadline.
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
  • Request and review a free copy of your credit report at annualcreditreport.com for any unfamiliar accounts or inquiries.
  • Monitor your bank and financial account statements closely for unauthorized activity.
  • Be alert for phishing attempts referencing this incident, and never share personal information in response to an unsolicited request.

File a Data Breach Lawsuit Against Orange Bank & Trust Company

If you received a notification letter from Orange Bank & Trust Company or believe your information was compromised in this incident, you may have legal options available to you. Financial institutions and the vendors they work with have a responsibility to protect the personal information entrusted to them, and when that data is exposed, affected customers can suffer real and lasting harm.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly specified
Date of Breach: On or about September 20, 2025
Date of Breach: December 2, 2025 to December 18, 2025 (incident at vendor Aesto Health)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.