Orange Bank & Trust Company (OB&T) has notified customers that their personal information may have been exposed as a result of a data security incident affecting Mercadien, P.C. CPAs, a third-party accounting and advisory firm the bank uses to support certain services. Companies that share customer data with outside vendors remain responsible for making sure that data stays protected, even when the exposure happens on a third party’s systems rather than their own.
Orange Bank & Trust Company’s Data Breach Investigation
According to a notification letter filed with the Massachusetts Attorney General’s Office, the incident involved Box.com, a third-party managed file transfer platform Mercadien uses to support the services it provides to OB&T and related institutions. Mercadien determined that unauthorized activity occurred within its Box.com environment between September 17, 2025, and October 8, 2025, during which unauthorized actors obtained vendor files that had been transferred through the platform. Those files reportedly included OB&T customer information. OB&T states that the incident did not involve any of its own internal systems and did not affect its ability to service customers. After a review of the affected files, OB&T determined on August 28, 2026, that one or more of the files may have contained an affected customer’s full name along with additional personal information. In response, Mercadien reported taking steps including resetting credentials, replacing firewall devices, and engaging third-party security experts, while OB&T is offering affected individuals complimentary access to Experian IdentityWorks credit monitoring.
Vendor-related data incidents like this one are an increasingly common source of exposure for financial institutions and their customers. Banks routinely share customer records with outside accounting, payroll, and processing vendors to support day-to-day operations, and each of those vendor relationships represents another potential point of failure outside the bank’s own direct control. When a vendor’s file-transfer or cloud storage platform is compromised, the exposure can affect customers of multiple client institutions at once, and the resulting investigation and notification timeline is often longer than a breach confined to a single company’s own systems, since the affected institution must first be notified by the vendor before it can assess and notify its own customers.
The letter notes that OB&T has no current evidence that the exposed information has been used for identity theft or financial fraud, but exposure of a customer’s full name in combination with other personal information taken from a financial institution’s records can still create longer-term fraud risk, particularly if the exposed files included any account or identifying details beyond a name. OB&T’s notice also discloses that 8 Rhode Island residents were affected by this incident; multi-state breach notices commonly report state-specific counts like this rather than a single nationwide total, since notification requirements vary state by state.
When Did This Breach Occur?
Mercadien determined that the unauthorized activity in its Box.com environment took place between September 17, 2025, and October 8, 2025. OB&T completed its review of the affected data and confirmed the impact to specific customers on August 28, 2026, and filed its notification with the Massachusetts Attorney General’s Office in September 2026.
What Information Was Breached?
Per OB&T’s notice, the review determined that one or more of the affected files may have contained the customer’s full name along with additional personal information contained in the vendor’s records. OB&T has not publicly detailed the full universal list of data types beyond name for every affected individual.
What You Can Do
If you received a notification letter from Orange Bank & Trust Company, consider taking the following steps to protect yourself:
- Enroll in the complimentary Experian IdentityWorks credit monitoring referenced in your notification letter before the enrollment deadline.
- Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
- Request and review a free copy of your credit report at annualcreditreport.com for any unfamiliar accounts or inquiries.
- Monitor your bank and financial account statements closely for unauthorized activity.
- Be alert for phishing attempts referencing this incident, and never share personal information in response to an unsolicited request.
File a Data Breach Lawsuit Against Orange Bank & Trust Company
If you received a notification letter from Orange Bank & Trust Company or believe your information was compromised in this incident, you may have legal options available to you. Financial institutions and the vendors they work with have a responsibility to protect the personal information entrusted to them, and when that data is exposed, affected customers can suffer real and lasting harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.