Citibank N.A.
bd_bb5a65fa71727a8f · schema v1 · pii pii-v1
Full breach record for Citibank N.A. →51 incidents on fileCitibank, N.A. notified the NH Attorney General that a Citi employee accidentally included an external email address when sending legitimate emails to customers. The misdelivered emails contained customer names, addresses, and credit card account numbers for three New Hampshire residents. The incident occurred on March 27, 2017. Citi closed the affected accounts, reissued cards, and offered 12 months of credit monitoring. The unintended recipient deleted the email without opening it.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 27, 2017
Begins
Mar 27, 2017
Discovered
Apr 11, 2017
Filed
vs. sector median
7 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Montana State AGbd_1700777c7280a0462017-04-11Candidate
- Massachusetts State AGbd_178ca65bb5fcf2812017-04-18 · +7dVerified
- Massachusetts State AGbd_6dddf4baedcd50172017-04-18 · +7dVerified
- Massachusetts State AGbd_4ef0bedccde586232017-04-20 · +9dVerified
Filing propagation · 5 filings · 3 states
View merged incident ↗Pattern: first filing Apr 11 (MT), last Apr 20 (MA) — a 9-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.