Capital One, National Association
ent_019e23035128cce2515f090474bfb979
Disclosures
25+
State AG · 5 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
198,419
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Capital One, National Association
- Normalized
- capital one national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 207ALC1P1YM0OVDV0K75
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- CAPITAL ONE FINANCIAL CORP— per GLEIF relationship records
Disclosure history (newest 25)newest first
- Indiana State AGas victim2026-01-27
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2025-05-05 and was reported on 2026-01-27. 1 Indiana residents were affected. 12 individuals affected in total.
- Indiana State AGas victim2026-01-12
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2025-12-26 and was reported on 2026-01-12. 2 Indiana residents were affected. 3 individuals affected in total.
- Maine State AGas victim2023-06-16
An employee of Capital One was involved in an incident of insider wrongdoing, resulting in the compromise of one Maine resident's personal information, including their Social Security number. The breach occurred between August 2022 and May 2023 and was discovered in March 2023. The company offered 24 months of credit monitoring services to the affected individual.
- Oregon State AGas victim2023-05-26
Capital One reported a data breach to the Oregon Attorney General. The breach was reported on 2023-05-26. The breach occurred during 2/1/2023 - 2/4/2023. The breach was discovered on 4/26/2023. 16,779 individuals were affected. Notice was sent on 5/26/2023.
- Maine State AGas reporting2023-05-26
Capital One, a financial services company, reported a data breach that occurred at a third-party vendor, NCB Management Services, Inc. The breach, an external system intrusion (hacking), took place from February 1, 2023, to February 4, 2023, and was discovered on April 26, 2023. It affected 222 Maine residents. The compromised information included names combined with financial account or credit/debit card numbers and their security codes. In response, the vendor is offering two years of identity monitoring services through Kroll.
- Massachusetts State AGas victim2023-02-17
Capital One, National Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-02-17. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-05-06
Capital One, National Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-06. 15 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-05-06
Capital One notified Montana residents that a former employee accessed customer account information and attempted to open credit card accounts without permission. The company found no evidence of data misuse or retention but offered two years of free credit monitoring. No suspicious activity was identified on affected accounts.
- Maine State AGas victim2021-05-06
Capital One, National Association, has issued a data breach notification out of an abundance of caution, stating that while customer data is at risk of future fraud, there is no evidence that the data has been breached. The incident, which occurred on August 20, 2020, and was discovered on April 6, 2021, affects 3 Maine residents. The compromised information includes financial account numbers or credit/debit card numbers, along with their corresponding security codes, access codes, passwords, or PINs. In response, the company is offering 24 months of free credit monitoring services through TransUnion's "myTrueIdentity" service.
- Maine State AGas victim2021-04-22
Capital One reported a data breach caused by insider wrongdoing that affected 219 individuals, including one resident of Maine. The breach occurred between September 2, 2020, and February 25, 2021, and was discovered on March 1, 2021. The compromised information includes names and financial account numbers or credit/debit card numbers along with their security codes or PINs. Capital One offered 24 months of free credit monitoring services to the affected individuals.
- Maine State AGas victim2021-04-01
Capital One reported a data security incident discovered on July 19, 2019, involving unauthorized access to an external system. The breach occurred on March 22-23, 2019. Capital One determined that the personal information of 198,419 customers, including Social Security numbers, was accessed. A follow-up notice was submitted to the Maine Attorney General on February 26, 2021, updating the count of affected Maine residents to 1,233. Affected individuals were offered 24 months of credit monitoring.
- Maine State AGas victim2021-03-22
Capital One, National Association, notified customers out of an abundance of caution that they were at risk of future fraud. The company stated there was no evidence that data has been breached.
- Maine State AGas victim2020-09-29
Capital One, National Association, reported a potential data compromise affecting 1,277 individuals, including 8 Maine residents. The incident occurred between May 15, 2020, and June 2, 2020, and was discovered on August 6, 2020. While the company stated there is no evidence that data has been breached, it issued notifications out of an abundance of caution as customers' Social Security numbers were at risk. The company offered 24 months of free credit monitoring services to affected individuals.
- Maine State AGas victim2020-09-25
Capital One, National Association reported a cybersecurity incident to the Maine Attorney General affecting 1,277 individuals, including 8 Maine residents. The breach occurred between May 15, 2020, and June 2, 2020, and was discovered on August 6, 2020. The company stated that customers are at risk of future fraud but there is no evidence that data was actually breached. Affected data included names and financial account or credit/debit card numbers. Capital One provided 2 years of free credit monitoring through TransUnion.
- Montana State AGas victim2020-08-19
Capital One issued a breach notification to Montana residents regarding unauthorized access to customer data. The incident involved the compromise of customer credentials. Affected data included names and Social Security numbers. Capital One provided two years of complimentary credit monitoring and identity restoration services through TransUnion.
- Montana State AGas victim2020-02-06
Capital One notified Montana residents that a former employee accessed personal information, including names, addresses, SSNs, DOBs, and credit card account numbers. The company offered two years of credit monitoring via TransUnion. The incident is contained; the former employee is no longer with the company.
- Montana State AGas victim2019-10-11
Capital One notified Montana residents that a former employee accessed personal information between Dec 1, 2018 and Apr 19, 2019. Data included names, addresses, SSNs, DOBs, and account numbers. Capital One provided two years of credit monitoring via TransUnion.
- Oregon State AGas victim2019-09-16
Capital One reported a data breach to the Oregon Attorney General. The breach was reported on 2019-09-16. The breach occurred during 3/22/2019 - 3/23/2019. The breach was discovered on 7/19/2019. Notice was sent on 8/8/20198/30/2019.
- Montana State AGas victim2019-08-08
Capital One notified Montana residents of a data breach involving unauthorized access to personal information including names, addresses, and financial account details. The company fixed the issue, engaged federal law enforcement, and offered credit monitoring services.
- Montana State AGas victim2019-08-08
Capital One notified Montana residents of a data breach occurring March 22-23, 2019, discovered July 19, 2019. An individual gained unauthorized access to credit card application and customer data, including names, SSNs (140,000), and bank account numbers (80,000). Capital One fixed the issue, worked with federal law enforcement, and offered two years of credit monitoring.
- Montana State AGas victim2019-02-07
Capital One Services, LLC issued a consumer notification to Montana residents regarding a breach involving unauthorized access via stolen credentials. The incident compromised personal information including names and Social Security numbers. Capital One provided two years of free credit monitoring and identity theft insurance to affected individuals.
- Montana State AGas victim2018-10-25
Capital One notified Montana residents that a former employee at a service provider accessed account information (name, address, DOB, SSN) between June 9 and July 23, 2018. The employee was terminated. Credit monitoring was offered.
- Massachusetts State AGas victim2017-12-11
Capital One, National Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-12-11. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2017-09-22
Capital One issued a supplemental notice to Montana residents regarding unauthorized account access via stolen credentials obtained through phishing. The fraudster accessed names, addresses, account numbers, and transaction history. Capital One locked accounts, reset passwords, and provided two years of TransUnion credit monitoring.
- Montana State AGas victim2017-07-31
Capital One Services, LLC notified Montana residents that a former employee accessed personal information between Jan 27 and Apr 20, 2017. Data included names, addresses, account numbers, DOB, and SSNs. Law enforcement was notified, the employee was terminated, and 2 years of credit monitoring were offered.