BANK OF AMERICA CORPORATION
bd_47e5c33000132e21 · schema v1 · pii pii-v1
Full breach record for BANK OF AMERICA CORPORATION →130 incidents on fileBank of America notified Massachusetts residents of an isolated mailing error on May 8, 2026, resulting in the disclosure of client relationship agreement documents. Affected data included names, addresses, dates of birth, Social Security numbers, and account numbers. The recipient returned the documents to the bank. Bank of America is monitoring accounts, has heightened security measures, and is offering two years of complimentary identity theft protection via Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
May 8, 2026
Begins
Jun 15, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_b1bdc37cd94e1e752026-07-30 · +45dCandidate
- Massachusetts State AGbd_9e88b4a7ea3755c52026-05-01 · +45dCandidate
- Massachusetts State AGbd_8a39a160ce10b5a22026-08-05 · +51dCandidate
Filing propagation · 4 filings
View merged incident ↗Pattern: first filing May 1 (MA), last Aug 5 (MA) — a 96-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.