AccidentalMisdeliveryCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
BANK OF AMERICA CORPORATION
bd_9e88b4a7ea3755c5 · schema v1 · pii pii-v1
Full breach record for BANK OF AMERICA CORPORATION →Bank of America notified Massachusetts residents of a data breach occurring on or about April 7, 2026. Trust tax return documents containing names, addresses, Social Security numbers, and account numbers were damaged in transit and subsequently returned to the bank. The incident involved both living customers and a decedent (Mary Mitchell). Bank of America conducted internal investigations, is monitoring accounts, and offered affected individuals a complimentary two-year identity theft protection membership through Experian IdentityWorks.
Massachusetts clock✓ MA AG ≤30d24 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_47e5c33000132e21Massachusetts State AGfiled 2026-06-01(31d gap)Candidate
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-680-bank-of-america/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- f7c569f7b77721b49c5d5aab8dfb5c6f16c908194558b92df45e5b13a7338da7
Reporting entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Victim entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Incident
- Discovered
- Apr 7, 2026
- Materiality determined
- —
- Notification sent
- May 1, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unknown
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.