PhysicalSkimmerCustomer Data InvolvedFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASICLowContained
Bank of the West
bd_e8bbdf7a7617d96a · schema v1 · pii pii-v1
Full breach record for Bank of the West →Bank of the West notified customers that ATM skimming devices installed on several ATMs compromised debit card numbers, PINs, and possibly names and addresses. The bank identified unauthorized withdrawal attempts on November 10, 2021, and contained the incident by taking ATMs offline and issuing new cards. Affected individuals were offered one year of credit monitoring.
California clockDiscovered Nov 10, 2021 → Notified Jun 23, 2022225d ✗ CA 60-day late32 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-554547
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 23, 2022
- Raw hash
- 106eec09191ad5b02896f513942966d4e760b0b75debb2237692fe5ba9ba11d6
Reporting entity
- Name
- Bank of the Westnorm: bank of the west
Victim entity
- Name
- Bank of the Westnorm: bank of the west
Incident
- Discovered
- Nov 10, 2021
- Materiality determined
- —
- Notification sent
- Jun 23, 2022
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSIDENTITY_BASIC
- Attack vector
- Unknown
- MITRE ATT&CK
- T1052 Exfiltration Over Physical Medium
- Threat actor
- ExternalFinancial
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- CA 60-day late · 225d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 10, 2021→ Notified: Jun 23, 2022225d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.