HackingIDENTITY_GOVERNMENTPIIMediumContained
HSBC BANK USA, NATIONAL ASSOCIATION
bd_409f71fd4684955a · schema v1 · pii pii-v1
Full breach record for HSBC BANK USA, NATIONAL ASSOCIATION →HSBC Card and Retail Services and HSBC Bank Nevada, N.A. notified the New Hampshire Attorney General on April 25, 2008, of a security incident involving its website's 'Forgot Login Password' page. Unauthorized third parties exploited a scripting vulnerability to view account information using account numbers and the last four digits of Social Security numbers. The incident affected 19 New Hampshire residents. HSBC strengthened authentication, issued new account numbers, and provided one year of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/hsbc-20080425.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 25, 2008
- Raw hash
- 80b02e988bc542d723915255e2d16646a84fad1601a6c407117d35f37e8b2088
Reporting entity
- Name
- HSBC BANK USA, NATIONAL ASSOCIATIONnorm: hsbc bank usa national
Victim entity
- Name
- HSBC BANK USA, NATIONAL ASSOCIATIONnorm: hsbc bank usa national
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Apr 14, 2008
- Affected individuals
- 19
- Data types
- IDENTITY_GOVERNMENTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.