U.S. BANCORP
ent_019e41c496609100e1f039cda0414ac7
Disclosures
3
SEC 10-K Item 1C · State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
333
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- U.S. BANCORP
- Normalized
- us bancorp— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- N1GZ7BBF3NP8GI976H15
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- usbank.com
Disclosure history (3)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-23
U.S. Bancorp's 2025 10-K filing (Exhibit 13) discloses 'Breaches in data security' and 'Failures or disruptions in or breaches of U.S. Bancorp's operational, technology or security systems' as standard risk factors. No specific incident, date, or victim entity is identified in the provided text.
- FEDERALSEC 10-K Item 1Cas reporting2025-02-21
U.S. Bancorp 2024 Annual Report (10-K Exhibit 13) management discussion and analysis. The document is a financial performance report covering FY2024. It references cybersecurity as a forward-looking risk factor (breaches in data security; failures or disruptions in operational, technology or security systems) but does not describe any specific cybersecurity incident or breach that occurred. No breach details are disclosed in this filing excerpt.
- 🦞Maine State AGas victim2021-05-05
U.S. Bank, N.A. reported a credential stuffing incident on March 31, 2021, affecting 333 individuals, including 2 Maine residents. The breach involved financial account numbers and credit/debit card details. The bank notified affected consumers via telephone on April 2, 2021.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of U.S. BANCORP — not by U.S. BANCORP itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🏛️Massachusetts State AGvia U.S. Bank National Association2026-07-01
U.S. Bank National Association notified Massachusetts residents of a security incident involving its service provider, FIS. Unauthorized access resulted in the exposure of cardholders' names, addresses, and credit card numbers. The incident was discovered on May 7, 2026. U.S. Bank is reissuing affected cards and offering one year of complimentary credit monitoring through TransUnion.
- 🐻California State AGvia U.S. Bank National Association2022-10-27
California Attorney General's Office received a data security breach notification from U.S. Bank, N.A. regarding an incident occurring on September 23, 2022. The filing is a sample submission (SB24 form). Specific details regarding the attack vector, data types, or number of affected individuals are not provided in the HTML metadata or attached sample letters.
- 🐻California State AGvia U.S. Bank National Association2021-02-03
A computer server containing customer personally identifiable information (names and Social Security numbers) was physically stolen from a U.S. Bank corporate office on or around July 30, 2020. U.S. Bank worked with authorities to recover the server and offered two years of free credit monitoring via myTrueIdentity/TransUnion to affected individuals. The information may have been up to 10 or more years old.
- 🦞Maine State AGvia U.S. Bank National Association2021-02-03
A network server belonging to U.S. Bank, N.A. was stolen, which resulted in the exposure of personal information. The breach occurred on July 30, 2020, and was discovered on August 21, 2020. One resident of Maine was affected. The compromised data included names and Social Security numbers. U.S. Bank offered 24 months of identity theft protection services to those affected.
- 🐻California State AGvia U.S. Bank National Association2020-12-22
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and Social Security numbers, of customers and related parties. The bank is offering two years of credit monitoring and identity restoration services to affected individuals.
- 🐻California State AGvia U.S. Bank National Association2020-12-09
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and Social Security numbers, of customers and related persons. The bank is offering two years of free credit monitoring and identity restoration services to affected individuals.
- 🦞Maine State AGvia U.S. Bank National Association2020-12-09
U.S. Bank, N.A. reported a cybersecurity incident on July 30, 2020, discovered on August 21, 2020, involving unauthorized access to a network server. The breach compromised names and Social Security Numbers of 2,052 individuals, including 3 Maine residents. The bank provided written notification on December 9, 2020, and offered 24 months of identity theft protection services.
- 🐻California State AGvia U.S. Bank National Association2020-11-23
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The stolen data included names, account numbers, Social Security numbers, and driver's license numbers. U.S. Bank is working with authorities to recover the server and has offered affected customers free credit monitoring, identity restoration services, and the option to obtain new account numbers.
- 🐻California State AGvia U.S. Bank National Association2020-11-06
On July 30, 2020, a computer server was physically stolen from a U.S. Bank corporate office. The server contained customer PII including names, account numbers, Social Security numbers, and credit card information. U.S. Bank worked with authorities to recover the server and offered affected customers free 2-year credit monitoring through TransUnion's myTrueIdentity service.
- 🐻California State AGvia U.S. Bank National Association2020-10-28
On July 30, 2020, a computer server containing customer personal information was physically stolen from a U.S. Bank corporate office. The data included names, account numbers, Social Security numbers, and driver's license numbers. U.S. Bank is working with authorities to recover the server and offering affected customers free credit monitoring and identity restoration services for two years.