MisuseData MishandlingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumResolved
JPMorgan Chase Bank, National Association
bd_ea611f83ec946f1b · schema v1 · pii pii-v1
Full breach record for JPMorgan Chase Bank, National Association →A Chase employee improperly downloaded customer information, including names, addresses, mortgage loan numbers, and Social Security numbers, to a personal computer and two online data storage sites on or around June 28, 2018. The data remained accessible to third parties for approximately three weeks. The employee was authorized to access the data but violated policy by using unapproved devices and sites. Chase deleted the data from the unauthorized locations and offered two years of free credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-138743
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 10, 2018
- Raw hash
- 2f199867106e7f87bc4e9568cf9724b97b382f94bdeff0dadb9a3823d23ed30a
Reporting entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Victim entity
- Name
- JPMorgan Chase Bank, National Associationnorm: jpmorgan chase bank national
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Insider
- Threat actor
- Internal
- Initial access
- insider_action
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.