Varo Bank, National Association
ent_019e6185b7bdd9834b95fa0f976de4d4
Disclosures
4
State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
7,007
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Varo Bank, National Association
- Normalized
- varo bank national— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 984500EFA2E7F0E11219
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- 🍁Vermont State AGas victim2024-05-07
Varo Bank, N.A. notified Vermont consumers of a data event discovered on March 12, 2024. Unauthorized third parties used customer credentials to access accounts. Potentially exposed data included names, addresses, emails, phone numbers, bank account numbers, and the last 4 digits of SSNs. Varo blocked the activity, investigated, and offered 12 months of credit monitoring via TransUnion.
- 🦬Montana State AGas victim2024-05-07
Varo Bank, N.A. reported a data breach to the Montana Attorney General. The breach was reported on 2024-05-07. The breach occurred on 3/12/2024. 13 Montana residents were affected.
- 🦞Maine State AGas victim2024-05-07
Varo Bank, N.A. reported a data breach affecting 7,007 individuals, which occurred on March 12, 2024, and was discovered on April 10, 2024. The breach was an external system hack that exposed names and financial account or payment card numbers along with their associated security codes, access codes, passwords, or PINs. The bank notified affected individuals electronically on May 7, 2024, and offered credit monitoring and identity restoration services.
- 🐻California State AGas victim2024-05-07
Varo Bank, N.A. notified customers that an unauthorized third party used valid credentials to access a subset of customer accounts between March 12 and March 18, 2024. The incident did not involve Varo's internal network. Affected data included name, address, email, phone, bank account number, and last 4 digits of SSN. Varo blocked the activity, investigated, and offered 12 months of credit monitoring.