U.S. Bank National Association
ent_019e413405107dac79d52f91a3cc2e2d
Disclosures
25+
State AG · 9 jurisdictions
Multi-filing incidents
5
incidents joining 2+ filings here
Max affected reported
2,052
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- U.S. Bank National Association
- Normalized
- us bank national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 6BYL5QZYBDK8S7L73M02
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- U.S. BANCORP— per GLEIF relationship records
Disclosure history (newest 25)newest first
- Vermont State AGas victim2026-09-09
U.S. Bank reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-09-09. The reporting organization type is Financial Services. 8 Vermont residents were affected. Categories of data breached: Social Security Numbers, Financial Account Codes, Credit and Debit Account Info.
- Massachusetts State AGas victim2026-07-31
U.S. Bank notified Massachusetts prepaid cardholders of unauthorized access to account data including names, addresses, email, account numbers, and SSNs. The incident involves prepaid cards. The bank provided two years of complimentary credit monitoring via TransUnion. No specific discovery or occurrence dates were provided in the notice.
- Nebraska State AGas victim2026-07-30
U.S. Bank notified Nebraska residents of unauthorized access to prepaid cardholder data. The incident potentially exposed names, addresses, email addresses, account numbers, and Social Security numbers. The bank offered two years of free credit monitoring via TransUnion and recommended fraud alerts or credit freezes. No specific discovery or occurrence dates were provided in the notification letter.
- Massachusetts State AGas victim2026-07-03
U.S. Bank National Association notified Massachusetts residents of a security incident involving its service provider, FIS. Unauthorized access resulted in the exposure of cardholders' names, addresses, and credit card numbers. The incident was discovered on May 7, 2026. U.S. Bank is reissuing affected cards and offering one year of complimentary credit monitoring through TransUnion.
- Illinois State AGas victim2026-07-01
U.S. BANK filed a data-breach notice with the Illinois Attorney General in July 2026 (case 26-07-1298). The register records the breach as discovered on April 20, 2026. Personal information types reported: financial account number. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2026-04-28
U.S. Bank issued an amended notice regarding a lost mortgage loan closing package from a title company. The package contained personal information including name, address, email, phone, date of birth, driver's license, account number, and other financial information. U.S. Bank is attempting to recover the package and has offered two years of credit monitoring via myTrueIdentity.
- Nebraska State AGas victim2025-09-30
State AG filing from Nebraska regarding U.S. Bank. The provided document content is empty (only page headers visible). No breach details, dates, or data types are extractable.
- Indiana State AGas reporting2025-06-13
US Bank reported a data breach to the Indiana Attorney General. The breach occurred on 2025-04-05 and was reported on 2025-06-13. 10 Indiana residents were affected. 1,569 individuals affected in total.
- Massachusetts State AGas victim2025-06-06
U.S. Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-06-06. 1 Massachusetts residents were affected.
- New Hampshire State AGas victim2025-03-24
U.S. Bank notified the New Hampshire Attorney General of a data event affecting one NH resident. On Feb 26, 2025, the bank detected unauthorized access to a third-party vendor's portal, leading to fraudulent changes in a pensioner's account. The bank suspended self-registration for payment changes and provided credit monitoring via TransUnion.
- California State AGas victim2022-10-27
California Attorney General's Office received a data security breach notification from U.S. Bank, N.A. regarding an incident occurring on September 23, 2022. The filing is a sample submission (SB24 form). Specific details regarding the attack vector, data types, or number of affected individuals are not provided in the HTML metadata or attached sample letters.
- Massachusetts State AGas victim2021-10-26
U.S. Bank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-10-26. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2021-05-05
U.S. Bank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-05. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-05-04
U.S. Bank filed a breach notification with the Montana Attorney General. The document is a binary Word file containing no extractable narrative text, preventing the identification of incident details, dates, or affected data.
- California State AGas victim2021-02-03
A computer server containing customer personally identifiable information (names and Social Security numbers) was physically stolen from a U.S. Bank corporate office on or around July 30, 2020. U.S. Bank worked with authorities to recover the server and offered two years of free credit monitoring via myTrueIdentity/TransUnion to affected individuals. The information may have been up to 10 or more years old.
- Maine State AGas victim2021-02-03
A network server belonging to U.S. Bank, N.A. was stolen, which resulted in the exposure of personal information. The breach occurred on July 30, 2020, and was discovered on August 21, 2020. One resident of Maine was affected. The compromised data included names and Social Security numbers. U.S. Bank offered 24 months of identity theft protection services to those affected.
- Massachusetts State AGas victim2021-02-03
U.S. Bank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-02-03. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-01-13
U.S. Bank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-13. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-12-22
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and Social Security numbers, of customers and related parties. The bank is offering two years of credit monitoring and identity restoration services to affected individuals.
- California State AGas victim2020-12-09
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and Social Security numbers, of customers and related persons. The bank is offering two years of free credit monitoring and identity restoration services to affected individuals.
- Maine State AGas victim2020-12-09
U.S. Bank, N.A. reported a cybersecurity incident on July 30, 2020, discovered on August 21, 2020, involving unauthorized access to a network server. The breach compromised names and Social Security Numbers of 2,052 individuals, including 3 Maine residents. The bank provided written notification on December 9, 2020, and offered 24 months of identity theft protection services.
- California State AGas victim2020-11-23
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The stolen data included names, account numbers, Social Security numbers, and driver's license numbers. U.S. Bank is working with authorities to recover the server and has offered affected customers free credit monitoring, identity restoration services, and the option to obtain new account numbers.
- California State AGas victim2020-11-06
On July 30, 2020, a computer server was physically stolen from a U.S. Bank corporate office. The server contained customer PII including names, account numbers, Social Security numbers, and credit card information. U.S. Bank worked with authorities to recover the server and offered affected customers free 2-year credit monitoring through TransUnion's myTrueIdentity service.
- California State AGas victim2020-10-28
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The data included names, account numbers, Social Security numbers, and driver's license numbers. U.S. Bank is working with authorities to recover the server and offering affected customers free credit monitoring and identity restoration services for two years.
- California State AGas victim2020-10-21
On July 30, 2020, a computer server was physically stolen from a U.S. Bank National Association corporate office. The server contained customer personally identifiable information including names and account numbers. U.S. Bank worked with authorities to recover the server and offered affected customers new account numbers. No fraudulent use of the information was identified at the time of notification.