DisclosureLens
AccidentalFinancial ServicesFinanceMisdeliveryCustomer Data InvolvedGovernment IDIdentity (basic)Financial accountMediumResolved

HSBC BANK USA, NATIONAL ASSOCIATION

bd_fd0a52b26eb60455 · schema v1 · pii pii-v2

Severity

Medium

Discovered

Aug 19, 2026

Filed

Sep 1, 2026

To disclose

Affected

Not disclosed

Confidence

69%
Full breach record for HSBC BANK USA, NATIONAL ASSOCIATION13 incidents on file

HSBC Bank USA mistakenly emailed documentation containing personal information, including Social Security numbers, telephone numbers, email addresses, and limited account identifiers, to an unintended recipient on August 18, 2026. The error was discovered on August 19, 2026. HSBC requested deletion of the email from the recipient's mailbox and obtained confirmation of deletion. Affected individuals are offered 24 months of credit monitoring and identity theft protection.

Incident timeline

undetected · 1 days

Aug 18, 2026

Begins

Aug 19, 2026

Discovered

Sep 1, 2026

Filed

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.