First State Bank of Middlebury Reports October 2025 Data Incident
Crystal Valley Financial Corporation, operating as First State Bank of Middlebury, reported an information security event to the Indiana Attorney General. This incident, which occurred in October 2025, is currently under investigation. Individuals who received a notification letter from the bank should carefully review it for details on how their personal information may be affected.
- State
- Indiana
- Breach date
- October 30, 2025
- Reported
- January 28, 2026
First State Bank of Middlebury, a division of Crystal Valley Financial Corporation, filed a data breach report with the Indiana Attorney General's office on January 28, 2026. This report details an information security incident that took place on October 30, 2025.
According to public filings, the nature of this breach type remains unspecified, and the specific categories of personal information involved have not been publicly disclosed. As a financial institution, First State Bank of Middlebury routinely handles sensitive personal data to facilitate banking and wealth management services. The company has indicated that the incident is currently under investigation.
Recipients of an official data breach notification letter from First State Bank of Middlebury should treat it as a critical document. Such a letter confirms that your personal information was part of this event. It is essential to read the letter thoroughly, as it is the primary source of specific details relevant to your situation.
While the specific data affected in this incident is not publicly detailed, it is always prudent to take general protective measures. Consider monitoring your financial accounts and credit reports for any suspicious activity. Remain vigilant against unexpected communications, such as emails or calls, that might attempt to solicit personal details, as these could be phishing attempts linked to data incidents. Following any instructions provided in the official notification letter is also highly recommended.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- Bozeman School District
- Teamsters Local 17
- Bank
- American Vanguard Corporation
- Graphic Information Systems Inc
- Arcadia of Benton LLC
- Arcadia of Bowling Green LLC
- Arcadia of Clarksville LLC
- Arcadia of Elizabethtown LLC
- Arcadia of Louisville LLC
- Hahn Loeser & Parks LLP
- Mather & Co CPAs LLC
- Graymont Inc
- Active Leadgen LLC dba ukvisaportal.com