MisusePrivilege AbuseData MishandlingSupply Chain (3P Vendor)Customer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMINORMediumContained
USAA Federal Savings Bank
bd_f27f736cf8e7739c · schema v1 · pii pii-v1
Full breach record for USAA Federal Savings Bank →USAA reported that call center representatives of a third-party service provider improperly shared USAA access credentials with unauthorized individuals between December 20, 2022, and May 18, 2023. This allowed unauthorized access to personal information of USAA members, including names, addresses, driver's license numbers, last four digits of SSNs, bank account numbers, and authentication PINs. USAA blocked the access and is monitoring accounts. Complimentary identity monitoring services were offered to affected adults and minors.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-568287
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 21, 2023
- Raw hash
- 327e8d29b0395f25f69f05de6226387e41b36898bf5d731ac0327799d9df47c8
Reporting entity
- Name
- United Services Automobile Associationnorm: united services automobile
Victim entity
- Name
- USAA Federal Savings Banknorm: usaa federal savings bank
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jun 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSMINOR
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Partner
- Third party
- via third-party service provider
- Initial access
- trusted_relationship
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.