HackingData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTPIILowContained
Compass Bank
bd_406f8c11c2feb12b · schema v1 · pii pii-v1
Full breach record for Compass Bank →Compass Bank notified California residents that an external contractor, BBVA Compass, improperly accessed personal and account information of a limited number of bank customers and prospects between January 1, 2018, and July 1, 2018. The data accessed may have included names, addresses, account numbers, SSNs, dates of birth, and phone numbers. The bank terminated the contractor's access and is offering one year of ExperianIDWorks Credit Plus 3B.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138459
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 1, 2018
- Raw hash
- efd764078f14680a81dbafad2b3db7baf05e3a957aceeed289d036a9d56bb641
Reporting entity
- Name
- Compass Banknorm: compass bank
- Domain
- compass-bank.com
Victim entity
- Name
- Compass Banknorm: compass bank
- Domain
- compass-bank.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Nov 30, 2018
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTPII
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- Partner
- Third party
- via BBVA Compass
- Initial access
- trusted_relationship
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.