Citibank N.A.
bd_bb5a65fa71727a8f · schema v1 · pii pii-v1
Full breach record for Citibank N.A. →Citibank, N.A. notified the New Hampshire Attorney General on April 11, 2017, regarding an incident affecting three New Hampshire residents. On approximately March 27, 2017, a Citi employee accidentally included an external email address in a legitimate email distribution list. The email contained customer names, addresses, and credit card account numbers. The unintended recipient deleted the email without opening it. Citi closed the affected accounts, reissued new credit cards, and offered 12 months of complimentary credit monitoring. The company assessed little risk of misuse.
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1700777c7280a046Montana State AGfiled 2017-04-11Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/citibank-20170411.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2017
- Raw hash
- d2de84b5a38d048cb76b6345cb0d2da793aa2995932ac4eb7eb4a73533b032d9
Reporting entity
- Name
- Citibank N.A.norm: citibank na
- Domain
- citi.com
Victim entity
- Name
- Citibank N.A.norm: citibank na
- Domain
- citi.com
Incident
- Discovered
- Mar 27, 2017
- Materiality determined
- —
- Notification sent
- Apr 11, 2017
- Affected individuals
- 3
- Data types
- PIIFINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- Internal
- Regulator citations
- Notified New Hampshire Attorney General
Compliance
- Time to disclose
- 15 days(15 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.