MisusePrivilege AbuseCustomer Data InvolvedTargetedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMediumContained
Citibank N.A.
bd_d8ce164c1b539e0d · schema v1 · pii pii-v1
Full breach record for Citibank N.A. →Citibank, N.A. reported a security incident in New Hampshire involving one resident. A Citi employee improperly accessed the resident's account between January 2020 and December 2021 to perform fraudulent online transactions. Personal information compromised included name, address, SSN, phone, account/card number, CVV, username, expiration date, and balance/credit limit. Citi reversed fraudulent transactions, closed accounts, reissued cards, and offered 12 months of credit monitoring. Notices were delivered by mail on February 24, 2022.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_216287a90d030deaMaine State AGfiled 2022-03-02Verified
- bd_f12f8711a59b7dbcMontana State AGfiled 2022-02-24(6d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/citibank-na-20220302.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 2, 2022
- Raw hash
- ee74e8686e4d466c3525238280f8bc7c2fa1396d29dce3faeb1c0362f214df89
Reporting entity
- Name
- Citibank N.A.norm: citibank na
- Domain
- citi.com
Victim entity
- Name
- Citibank N.A.norm: citibank na
- Domain
- citi.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Feb 24, 2022
- Affected individuals
- 1
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- InternalFinancial
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.