DisclosureLens
MisuseIdentity (basic)Government IDFinancial accountFinancial credentialsMediumContained

CAPITAL ONE SERVICES, LLC

bd_060db34ad1e81c6a · schema v1 · pii pii-v2

Severity

Medium

Discovered

Sep 2, 2025

Filed

Nov 20, 2025

To disclose

Affected

1state residents only

Confidence

66%
Full breach record for CAPITAL ONE SERVICES, LLC87 incidents on file

Capital One notified the Nebraska Attorney General of a cybersecurity incident involving one Nebraska resident. A now-former service provider employee accessed Capital One US Card customer accounts and attempted unauthorized transactions between May 20, 2025, and July 8, 2025. Capital One discovered the incident on September 2, 2025, and sent a notification letter to the affected resident on November 17, 2025, offering 24 months of free credit monitoring.

Incident timeline

undetected · 105 days

May 20, 2025

Begins

Sep 2, 2025

Discovered

Nov 20, 2025

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.