DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Government IDIdentity (basic)Financial accountMediumActive

Comerica Bank

bd_9a6ddb45ae0711da · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jul 30, 2012

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

68%
Full breach record for Comerica Bank3 incidents on file

Comerica Bank reported a security incident involving unauthorized access to merchant application data hosted by third-party processor Global Payments, Inc. The breach potentially exposed personal information from merchant applications, including names, Social Security numbers, and business bank account numbers. The incident was discovered in June 2024. Comerica notified affected individuals, offering one year of free credit monitoring and identity protection services through Equifax. The investigation into whether data was actually exfiltrated was ongoing at the time of notification.

Incident timeline — partial

? — ?

Breach window unknown

Jul 30, 2012

Filed

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
California State AGJul 30 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.