BANK OF AMERICA CORPORATION
ent_019dea4e89b272f3ee5c58402fb83dd1
Disclosures
12
State AG · 5 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
57,028
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- BANK OF AMERICA CORPORATION
- Normalized
- bank of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 9DJT3UXIJIZJI4WXO774
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- bankofamerica.com
Disclosure history (12)newest first
- 🏛️Massachusetts State AGas victim2026-06-01
Bank of America notified Massachusetts residents of a cybersecurity incident occurring on May 8, 2026, involving an isolated mailing error. Customer information, including names, addresses, dates of birth, Social Security numbers, and account numbers, was disclosed. The bank implemented heightened security, monitors accounts for suspicious activity, and offers two years of complimentary identity theft protection via Experian IdentityWorks.
- 🏛️Massachusetts State AGas victim2026-05-01
Bank of America notified Massachusetts residents of a data breach occurring on or about April 7, 2026. Trust tax return documents containing names, addresses, Social Security numbers, and account numbers were damaged in transit and subsequently returned to the bank. The incident involved both living customers and a decedent (Mary Mitchell). Bank of America conducted internal investigations, is monitoring accounts, and offered affected individuals a complimentary two-year identity theft protection membership through Experian IdentityWorks.
- 🦞Maine State AGas victim2025-03-03
Bank of America reported an inadvertent disclosure affecting one Maine resident. The breach was discovered on February 19, 2025, and occurred the day before. Affected individuals were offered 24 months of credit monitoring services through Experian.
- 🦞Maine State AGas victim2025-01-03
Bank of America reported a data breach to the Maine AG with an occurrence date of October 1, 2024 and discovery date of October 24, 2024. A total of 414 individuals were affected, including 1 Maine resident. The breach type was listed as 'Other' with no further technical detail in the filing. Consumer notification was sent January 3, 2025. Experian credit monitoring (24 months) was offered to affected individuals.
- 🦞Maine State AGas victim2024-06-12
Bank of America reported an inadvertent disclosure incident that occurred on April 16, 2024 and was discovered on April 22, 2024. A total of 2,676 individuals were affected nationally, including 18 Maine residents. The breach was categorized as an inadvertent disclosure (error). Written notifications were sent on June 12, 2024. Experian Credit Monitoring was offered for 24 months to affected individuals.
- 🌴South Carolina State AGas victim2024-02-15
South Carolina state-agency notice filed by Bank of America, N.A. The source PDF extraction returned empty text content (4 pages read, 0 words extracted). No breach details, dates, or affected counts are available in the provided source.
- 🦞Maine State AGas victim2024-02-02
Bank of America, N.A. reported an external system breach (hacking) occurring on October 29, 2023, discovered on October 30, 2023. The incident affected 57,028 individuals nationwide, including 93 Maine residents. Personal information acquired included names and Social Security Numbers. Bank of America provided written notification and offered 24 months of complimentary identity theft protection services via Experian.
- 🌴South Carolina State AGas victim2023-04-04
South Carolina Attorney General's office received a breach notification from Bank of America, N.A. The source PDF text extraction returned empty content, preventing extraction of specific incident details, dates, or affected counts.
- 🦬Montana State AGas victim2023-03-24
Bank of America, N.A. reported a data breach to the Montana Attorney General. The breach was reported on 2023-03-24. The breach occurred on 2/1/2023. 901 Montana residents were affected.
- 🐻California State AGas victim2020-05-18
Bank of America disclosed that on April 22, 2020, it uploaded client loan application data to an SBA test platform where it may have been visible to other authorized lenders and vendors. The data included names, addresses, SSNs, and tax IDs. Bank of America confirmed removal of the data the same day and offered two years of identity theft protection. No misuse was indicated.
- 🐻California State AGas victim2015-06-25
Bank of Manhattan Mortgage Lending reported an incident where an employee mishandled mortgage loan files stored on a removable disk drive, potentially resulting in unauthorized disclosure. Affected data includes names, addresses, Social Security numbers, birth dates, and financial information. The company recovered the drive, notified law enforcement, and is offering 12 months of identity theft protection and $1 million in identity theft insurance to affected individuals.
- 🐻California State AGas victim2012-05-29
Bank of America Merchant Services (BAMS) disclosed that its service provider, First Data Corporation, shared personal information of BAMS merchants with three firms for testing verification and anti-fraud services in January and February 2012. The data included names, addresses, and Social Security numbers. BAMS offered affected merchants one year of complimentary credit monitoring through Experian's Triple Advantage program.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of BANK OF AMERICA CORPORATION — not by BANK OF AMERICA CORPORATION itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.