AccidentalMisdeliveryCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENTMediumResolved
HSBC BANK USA, NATIONAL ASSOCIATION
bd_8d93fd54828d3679 · schema v1 · pii pii-v1
Full breach record for HSBC BANK USA, NATIONAL ASSOCIATION →HSBC Bank USA notified customers that its mortgage servicing provider inadvertently sent encrypted disks containing personal information (names, SSNs, account numbers) to an unauthorized third-party analytics firm between Dec 7-8, 2015. The third party returned the disks without accessing the data. HSBC offered one year of identity monitoring.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_01cde2a6a6f9a67fMontana State AGfiled 2016-01-13Candidate
- bd_07ec4f9d069d4917Washington State AGfiled 2016-01-13Verified
- bd_23bc93e9cc844bb0Oregon State AGfiled 2016-01-14(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59603
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 13, 2016
- Raw hash
- 817b3ca9b8d82dc4e16db95e5ded31d140dcda6ed16b9780674bf6b3b7bb7f6b
Reporting entity
- Name
- HSBC BANK USA, NATIONAL ASSOCIATIONnorm: hsbc bank usa national
Victim entity
- Name
- HSBC BANK USA, NATIONAL ASSOCIATIONnorm: hsbc bank usa national
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTEMPLOYMENT
- Attack vector
- Unknown
- Third party
- via mortgage servicing provider
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.