HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALSMediumContained
JPMorgan Chase Bank, National Association
bd_c86bde4f8a659c48 · schema v1 · pii pii-v1
Full breach record for JPMorgan Chase Bank, National Association →JPMorgan Chase Bank, N.A. disclosed a security incident affecting California residents regarding [PROGRAM NAME] cards. Unauthorized access occurred from mid-July to mid-September 2013, potentially exposing names, addresses, SSNs, card numbers, and bank account details. The company secured systems, launched an investigation with law enforcement, and offered one year of free credit monitoring. No evidence of improper use was found.
California clockDiscovered Sep 15, 2013 → Notified Dec 5, 201381d ✗ CA 60-day late12 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_e04ef8413778bb47Hawaii State AGfiled 2013-12-09(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-43435
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 5, 2013
- Raw hash
- ba649332c2f0eb463a891325a98e743e1d4a77c187d9bb878975ccb45e4a0a8d
Reporting entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Victim entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Incident
- Discovered
- Sep 15, 2013
- Materiality determined
- —
- Notification sent
- Dec 5, 2013
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 12 weeks(81 days from discovery to filing)
- Compliance flags
- CA 60-day late · 81d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 15, 2013→ Notified: Dec 5, 201381d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.