Citibank N.A.
ent_019e61661a19065b2f4506171299466c
Disclosures
25+
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
230
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Citibank N.A.
- Normalized
- citibank na— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- citi.com
Disclosure history (newest 25)newest first
- Massachusetts State AGas victim2025-07-24
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-07-24. 2 Massachusetts residents were affected.
- Massachusetts State AGas victim2024-11-19
Citibank, NA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-11-19. 2 Massachusetts residents were affected.
- Massachusetts State AGas victim2024-09-04
CitiBank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-09-04. 1 Massachusetts residents were affected.
- Massachusetts State AGas victim2024-06-05
Citibank, N.A reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-06-05. 1 Massachusetts residents were affected.
- Montana State AGas victim2024-03-01
Citibank, N.A. notified affected individuals of an insider security incident where an employee improperly accessed systems between Sept 7, 2023 and Jan 2, 2024. Compromised data included names, SSNs, DOBs, and credit card details. The employee was placed on leave, cards were reissued, and credit monitoring was offered.
- Massachusetts State AGas victim2023-12-18
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-18. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2023-12-06
Citibank NA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-12-06. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2023-06-30
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-30. 8 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2023-06-23
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-23. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2023-05-16
Citibank, N.A. notified Montana residents of an insider threat incident where an employee improperly accessed credit card and personal information between Jan 26 and Apr 10, 2023. Affected data included SSN, DOB, and full card details. The employee was terminated, cards reissued, and credit monitoring offered.
- Massachusetts State AGas victim2023-01-30
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-01-30. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2022-03-24
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-03-24. 6 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGas victim2022-03-02
Citibank, N.A. reported an insider wrongdoing incident affecting 230 individuals, including 1 Maine resident. The breach occurred between January 1, 2020, and June 1, 2021, and was discovered on December 14, 2021. Acquired data included names and financial account or credit/debit card numbers (with security codes/PINs). Consumers received written notification on February 24, 2022, and were offered 12 months of credit monitoring through Experian.
- New Hampshire State AGas victim2022-03-02
Citibank, N.A. reported a security incident in New Hampshire involving one resident. A Citi employee improperly accessed the resident's account between January 2020 and December 2021 to perform fraudulent online transactions. Personal information compromised included name, address, SSN, phone, account/card number, CVV, username, expiration date, and balance/credit limit. Citi reversed fraudulent transactions, closed accounts, reissued cards, and offered 12 months of credit monitoring. Notices were delivered by mail on February 24, 2022.
- Montana State AGas victim2022-02-24
Citibank, N.A. notified Montana residents that an employee improperly accessed customer accounts between January 2020 and December 2021 to perform fraudulent transactions. Affected data included names, SSNs, account numbers, and CVVs. Citibank reversed transactions, closed accounts, issued new cards, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2022-02-22
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-02-22. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2022-01-01
CITIBANK filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-175). The register records the breach as discovered on January 1, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2021-10-11
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-10-11. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-01-28
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-01-28. 2 Massachusetts residents were affected. The report records the breach type as both.
- Massachusetts State AGas victim2019-07-15
Citybank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-07-15. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2019-05-02
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-05-02. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2019-04-15
Citibank NA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-04-15. 8 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2018-12-03
Citibank NA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-03. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-10-16
Citibank NA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-10-16. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-04-20
Citibank, N.A. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-04-20. 2 Massachusetts residents were affected. The report records the breach type as electronic.