AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
BANK OF AMERICA CORPORATION
bd_e5cec6cb4b1f309f · schema v1 · pii pii-v1
Full breach record for BANK OF AMERICA CORPORATION →Bank of America disclosed that on April 22, 2020, it uploaded client loan application data to an SBA test platform where it may have been visible to other authorized lenders and vendors. The data included names, addresses, SSNs, and tax IDs. Bank of America confirmed removal of the data the same day and offered two years of identity theft protection. No misuse was indicated.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-190091
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2020
- Raw hash
- 5981eabf2d71008b7980933825575b81c74812fdd679e094371c69946337befb
Reporting entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Victim entity
- Name
- BANK OF AMERICA CORPORATIONnorm: bank of america
- Domain
- bankofamerica.com
Incident
- Discovered
- Apr 22, 2020
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- Third party
- via Small Business Administration (SBA)
Compliance
- Time to disclose
- 26 days(26 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.