DisclosureLens
HackingFinancial ServicesFinanceSupply Chain (3P Vendor)Customer Data InvolvedIdentity (basic)Government IDMediumContained

OneWest Bank, FSB

bd_83a67c48f4e25596 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Apr 23, 2013

To disclose

Affected

Not disclosed

Confidence

65%
Full breach record for OneWest Bank, FSB

OneWest Bank, FSB notified customers that a third-party service provider suffered a network intrusion during Q1 2011. Unauthorized access exposed customer names, addresses, birthdates, phone numbers, driver's license numbers, passport numbers, and Social Security Numbers. The bank states it does not believe data was copied or downloaded. The service provider cooperated with the US Secret Service and engaged forensic firms. OneWest offered 12 months of free credit monitoring.

Incident timeline

Jan 1, 2011

Begins

Apr 23, 2013

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.