DisclosureLens
MisuseFinancial ServicesFinanceData MishandlingCustomer Data InvolvedIdentity (basic)Financial accountFinancial credentialsLowContained

CITIZENS BANK

bd_768e10564a819bb4 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Aug 10, 2026

To disclose

Affected

8state residents only

Confidence

65%
Full breach record for CITIZENS BANK14 incidents on file

Citizens Bank notified customers that their account information (name, address, credit/debit card number, expiration, and security code) was accessed outside authorized business purposes and shared with a third-party vendor between April 23, 2026, and May 15, 2026. The bank issued replacement cards for affected accounts and offered two years of complimentary credit monitoring and identity protection services.

Leak gap clock Leak >90d
no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.

Incident timeline

Apr 23, 2026

Begins

Aug 10, 2026

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed8 affectedView incident
A leak claim by everest about this victim predates this filing by 111 days.View originating leak claim

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.