U.S. Bank National Association
ent_019e413405107dac79d52f91a3cc2e2d
Disclosures
17
State AG · 4 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
14,108
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- U.S. Bank National Association
- Normalized
- us bank national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6BYL5QZYBDK8S7L73M02
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- U.S. BANCORP— per GLEIF relationship records
Disclosure history (17)newest first
- 🏛️Massachusetts State AGas victim2026-07-01
U.S. Bank National Association notified Massachusetts residents of a security incident involving its service provider, FIS. Unauthorized access resulted in the exposure of cardholders' names, addresses, and credit card numbers. The incident was discovered on May 7, 2026. U.S. Bank is reissuing affected cards and offering one year of complimentary credit monitoring through TransUnion.
- 🐻California State AGas victim2022-10-27
California Attorney General's Office received a data security breach notification from U.S. Bank, N.A. regarding an incident occurring on September 23, 2022. The filing is a sample submission (SB24 form). Specific details regarding the attack vector, data types, or number of affected individuals are not provided in the HTML metadata or attached sample letters.
- 🐻California State AGas victim2021-02-03
A computer server containing customer personally identifiable information (names and Social Security numbers) was physically stolen from a U.S. Bank corporate office on or around July 30, 2020. U.S. Bank worked with authorities to recover the server and offered two years of free credit monitoring via myTrueIdentity/TransUnion to affected individuals. The information may have been up to 10 or more years old.
- 🦞Maine State AGas victim2021-02-03
A network server belonging to U.S. Bank, N.A. was stolen, which resulted in the exposure of personal information. The breach occurred on July 30, 2020, and was discovered on August 21, 2020. One resident of Maine was affected. The compromised data included names and Social Security numbers. U.S. Bank offered 24 months of identity theft protection services to those affected.
- 🐻California State AGas victim2020-12-22
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and Social Security numbers, of customers and related parties. The bank is offering two years of credit monitoring and identity restoration services to affected individuals.
- 🐻California State AGas victim2020-12-09
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and Social Security numbers, of customers and related persons. The bank is offering two years of free credit monitoring and identity restoration services to affected individuals.
- 🦞Maine State AGas victim2020-12-09
U.S. Bank, N.A. reported a cybersecurity incident on July 30, 2020, discovered on August 21, 2020, involving unauthorized access to a network server. The breach compromised names and Social Security Numbers of 2,052 individuals, including 3 Maine residents. The bank provided written notification on December 9, 2020, and offered 24 months of identity theft protection services.
- 🐻California State AGas victim2020-11-23
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The stolen data included names, account numbers, Social Security numbers, and driver's license numbers. U.S. Bank is working with authorities to recover the server and has offered affected customers free credit monitoring, identity restoration services, and the option to obtain new account numbers.
- 🐻California State AGas victim2020-11-06
On July 30, 2020, a computer server was physically stolen from a U.S. Bank corporate office. The server contained customer PII including names, account numbers, Social Security numbers, and credit card information. U.S. Bank worked with authorities to recover the server and offered affected customers free 2-year credit monitoring through TransUnion's myTrueIdentity service.
- 🐻California State AGas victim2020-10-28
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The data included names, account numbers, Social Security numbers, and driver's license numbers. U.S. Bank is working with authorities to recover the server and offering affected customers free credit monitoring and identity restoration services for two years.
- 🐻California State AGas victim2020-10-21
On July 30, 2020, a computer server was physically stolen from a U.S. Bank National Association corporate office. The server contained customer personally identifiable information including names and account numbers. U.S. Bank worked with authorities to recover the server and offered affected customers new account numbers. No fraudulent use of the information was identified at the time of notification.
- 🐻California State AGas victim2020-10-14
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The data included names, account numbers, Social Security numbers, driver's license numbers, and dates of birth. U.S. Bank is working with authorities to recover the server and is offering affected customers free credit monitoring and identity restoration services for two years.
- 🦞Maine State AGas victim2020-10-14
U.S. Bank, N.A. reported a data breach involving the loss or theft of a device containing customer information. The incident occurred and was discovered on July 30, 2020. It affected 2,000 individuals, compromising names and financial account numbers with associated access codes. Written notifications were sent to affected parties on October 14, 2020.
- 🐻California State AGas victim2020-09-29
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The data included names, account numbers, Social Security numbers, and in some cases driver's license numbers and dates of birth. U.S. Bank is offering two years of free credit monitoring and identity restoration services to affected individuals.
- 🦫Oregon State AGas victim2020-09-18
U.S. Bank, N.A. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-18. The breach occurred during 7/30/2020 - 7/30/2020. The breach was discovered on 8/21/2020. 14,108 individuals were affected. Notice was sent on 9/18/2020.
- 🦞Maine State AGas victim2020-09-18
U.S. Bank, N.A. reported a data breach involving the loss or theft of a device or media, such as a computer, laptop, or external hard drive. The breach occurred on July 30, 2020, and was discovered on August 21, 2020. The compromised information includes names and financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. Four Maine residents were affected by this incident.
- 🐻California State AGas victim2020-09-18
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and account numbers. The bank is working with authorities to recover the server and offering affected customers new account numbers. No fraudulent use was known at the time of notification.