AccidentalLossData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
REGIONS FINANCIAL CORPORATION
bd_4ac52b4a8a274020 · schema v1 · pii pii-v1
Full breach record for REGIONS FINANCIAL CORPORATION →Regions Financial Corporation reported a data security breach involving the loss of a USB flash drive containing personal information of individuals enrolled in its 401(k) plan. The incident involved Ernst & Young LLP, Regions' audit firm, which mailed a drive containing names, Social Security numbers, and dates of birth to another office. The drive was lost in transit, though the device was encrypted (with the password included in the package). Regions offered one year of free credit monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-22147
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 23, 2012
- Raw hash
- 3f186bc72e75e8129d08b2eadccaa7048198f84ce38dabc6f5b75ed866b2686b
Reporting entity
- Name
- REGIONS FINANCIAL CORPORATIONnorm: regions financial
Victim entity
- Name
- REGIONS FINANCIAL CORPORATIONnorm: regions financial
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- Partner
- Regulator citations
- Submitted Breach Notification to California Office of the Attorney General
- Third party
- via Ernst & Young LLP
- Initial access
- removable_media
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.