Comerica Bank
bd_9a6ddb45ae0711da · schema v1 · pii pii-v1
Full breach record for Comerica Bank →Comerica Bank reported a security incident involving unauthorized access to merchant application data hosted by third-party processor Global Payments, Inc. The breach potentially exposed personal information from merchant applications, including names, Social Security numbers, and business bank account numbers. The incident was discovered in June 2024. Comerica notified affected individuals, offering one year of free credit monitoring and identity protection services through Equifax. The investigation into whether data was actually exfiltrated was ongoing at the time of notification.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-32376
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 30, 2012
- Raw hash
- e5bad71546ab7dcef36921d713cce94aa9e0a76ef95625facb4d2f8d7f30908c
Reporting entity
- Name
- Comerica Banknorm: comerica bank
- Industry
- financial_services
Victim entity
- Name
- Comerica Banknorm: comerica bank
- Industry
- financial_services
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed breach notification with California Office of the Attorney General
- Third party
- via Global Payments, Inc.
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.