MisusePrivilege AbuseData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
BANK OF AMERICA CORPORATION
bd_6dceac8ebff00243 · schema v1 · pii pii-v1
Full breach record for BANK OF AMERICA CORPORATION →Bank of America notified the New Hampshire Attorney General of a breach involving one NH resident. A former employee accessed customer data for fraud purposes between April 6, 2021, and September 18, 2021. Exposed data included PII, SSN, and financial account details. The resident was notified on December 21, 2021, and offered two years of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/bank-american-20211220.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 20, 2021
- Raw hash
- efc8e6841fa3ca833983cc38e7fc62e1826eef5d2bcafe90e0856ff0a042aee4
Reporting entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Victim entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Incident
- Discovered
- Sep 18, 2021
- Materiality determined
- —
- Notification sent
- Dec 21, 2021
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Initial access
- insider_action
Compliance
- Time to disclose
- 13 weeks(93 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.