AccidentalMisdeliveryCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
BANK OF AMERICA CORPORATION
bd_47e5c33000132e21 · schema v1 · pii pii-v1
Full breach record for BANK OF AMERICA CORPORATION →Bank of America notified Massachusetts residents of a cybersecurity incident occurring on May 8, 2026, involving an isolated mailing error. Customer information, including names, addresses, dates of birth, Social Security numbers, and account numbers, was disclosed. The bank implemented heightened security, monitors accounts for suspicious activity, and offers two years of complimentary identity theft protection via Experian IdentityWorks.
Massachusetts clock✓ MA AG ≤30d24 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_9e88b4a7ea3755c5Massachusetts State AGfiled 2026-05-01(31d gap)Candidate
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-979-bank-of-america/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- 008b8cc2e3b3b6bc413d6a5249a1ca1eaa2628d8094641d87e78579a64ac3f9a
Reporting entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Victim entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Incident
- Discovered
- May 8, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unknown
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.