HSBC USA INC.
ent_019e44fed6b8d4b25e3c959daad86601
Disclosures
2
SEC 10-K Item 1C · 1 jurisdiction
Incidents
—
no linked incident in sample
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HSBC USA INC.
- Normalized
- hsbc usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300LBOHZ4QSIWU288
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- FEDERALSEC 10-K Item 1Cas reporting2026-02-25
HSBC USA Inc. filed Item 1C of its 10-K disclosing its cybersecurity risk management program. The filing states that no cybersecurity incidents have materially affected the company to date. It details a 'Three Lines of Defense' governance structure, technical controls (IDS/IPS, DDoS prevention), and third-party risk management processes. No specific breach or incident is reported.
- FEDERALSEC 10-K Item 1Cas victim2024-02-21
HSBC USA Inc.'s 10-K Item 1C cybersecurity disclosure describes its risk-management program, three-lines-of-defense structure, board/Risk Committee oversight, and reliance on HSBC Group and Americas Regional CISO leadership. The filing states risks from cybersecurity threats, including prior incidents, have not materially affected the company to date, and notes an observed increase in ransomware attacks against its suppliers without material impact. No specific incident is disclosed.
Subsidiary disclosures (8)filed by group companies
◈ These filings were made by or about subsidiaries of HSBC USA INC. — not by HSBC USA INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- 🐻California State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2018-11-02
HSBC Bank USA reported unauthorized access to online banking accounts between October 4 and October 14, 2018. Affected data included names, addresses, account numbers, balances, and transaction history. HSBC suspended access, reset credentials, enhanced authentication, and offered one year of identity monitoring.
- 🦫Oregon State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2016-01-14
HSBC Bank USA, National Association reported a data breach to the Oregon Attorney General. The breach was reported on 2016-01-14. The breach occurred during 12/7/2015 - 12/8/2015. The breach was discovered on 12/10/2015. 432,095 individuals were affected. Notice was sent on 1/11/2016.
- 🦬Montana State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2016-01-13
HSBC Bank, USA reported a data breach to the Montana Attorney General. The breach was reported on 2016-01-13. The breach occurred from 12/7/2015 to 12/8/2015. 80 Montana residents were affected.
- 🌲Washington State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2016-01-13
HSBC Bank USA, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2015-12-10 and filed notice on 2016-01-13. 5,270 Washington residents were affected. 34 days elapsed between awareness and notification. 3 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2016-01-13
HSBC Bank USA notified customers that its mortgage servicing provider inadvertently sent encrypted disks containing personal information (names, SSNs, account numbers) to an unauthorized third-party analytics firm between Dec 7-8, 2015. The third party returned the disks without accessing the data. HSBC offered one year of identity monitoring.
- 🐻California State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2015-07-24
HSBC Bank USA, National Association disclosed that account details, including name, account number, property address, loan and payment details, were sent in error to a commercial entity not associated with HSBC. The third party did not view the data and deleted it. HSBC offered one year of credit monitoring and identity theft protection to affected individuals.
- 🐻California State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2012-10-30
HSBC Bank USA National Association notified customers that a resigned employee took account information in late July 2012. Affected data included names, phone numbers, account numbers, and potentially Social Security numbers. HSBC offered one year of credit monitoring.
- ⛰️New Hampshire State AGvia HSBC BANK USA, NATIONAL ASSOCIATION2008-04-25
HSBC Card and Retail Services and HSBC Bank Nevada, N.A. notified the New Hampshire Attorney General on April 25, 2008, of a security incident involving its website's 'Forgot Login Password' page. Unauthorized third parties exploited a scripting vulnerability to view account information using account numbers and the last four digits of Social Security numbers. The incident affected 19 New Hampshire residents. HSBC strengthened authentication, issued new account numbers, and provided one year of credit monitoring.