United Services Automobile Association
ent_9bca9a7bfcf398d4fc77b5bf
Disclosures
8
State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
32,276
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- United Services Automobile Association
- Normalized
- united services automobile— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- California State AGas victim2024-08-29
USAA disclosed a data breach affecting California members due to a system error during a routine update to its document delivery system between April 13 and April 30, 2024. The error resulted in the inadvertent posting of some members' documents, including PII, PHI, and financial data, to other members' online accounts. USAA removed the documents, investigated the incident, and enhanced IT change management processes. Affected individuals were offered two years of Experian IdentityWorks.
- Maine State AGas victim2024-08-28
USAA disclosed a data incident where a system error during a routine update to its document delivery system caused personal information to be inadvertently posted to the wrong member's online account. The breach occurred between April 13 and April 30, 2024, and was discovered on July 31, 2024. Approximately 32,276 individuals were affected, including 156 Maine residents. Data exposed included names, addresses, SSNs, driver's license numbers, and health information. USAA notified affected individuals on August 27, 2024, and offered two years of credit monitoring.
- Vermont State AGas victim2023-06-22
USAA notified Vermont consumers of a data incident where unauthorized individuals accessed member information via stolen credentials from a third-party call center provider. The incident occurred between Dec 2022 and May 2023. Affected data included names, addresses, DOB, driver's license numbers, partial SSNs, bank account numbers, and PINs. USAA blocked access, is monitoring accounts, and offered two years of Experian IdentityWorks.
- Montana State AGas victim2021-06-03
USAA notified Montana residents that on May 6, 2021, fraudsters used stolen personal information to gain unauthorized access to driver's license numbers via the auto insurance quote process on usaa.com. USAA blocked access, identified impacted individuals, and offered two years of Experian IdentityWorks. Driver's license numbers were the primary data type compromised.
- Massachusetts State AGas victim2018-05-10
United Service Automobile Assocition reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-05-10. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2014-08-04
United Services Automobile Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-08-04. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2013-08-16
Untied Services Automobile Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-08-16. 2 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2012-09-17
United Services Automobile Association reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-09-17. 1 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of United Services Automobile Association — not by United Services Automobile Association itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Oregon State AGvia USAA Federal Savings Bank2024-08-29
USAA reported a data breach to the Oregon Attorney General. The breach was reported on 2024-08-29. The breach occurred during 4/13/2024 - 4/30/2024. The breach was discovered on 7/31/2024. 32,276 individuals were affected. Notice was sent on 8/27/2024.
- Indiana State AGvia USAA Federal Savings Bank2024-08-27
USAA reported a data breach to the Indiana Attorney General. The breach occurred on 2024-04-13 and was reported on 2024-08-27. 245 Indiana residents were affected. 32,276 individuals affected in total.
- Washington State AGvia USAA Federal Savings Bank2023-06-21
USAA notified Washington AG of a data incident involving a third-party service provider. Between Dec 20, 2022 and May 18, 2023, unauthorized individuals accessed USAA member credentials shared by call center reps. Affected data included names, addresses, DOB, driver's license numbers, last 4 digits of SSN, bank/card numbers, and PINs. USAA blocked access, offered 2-year Experian IdentityWorks membership, and enhanced security controls. No fraud identified.
- California State AGvia USAA Federal Savings Bank2023-06-21
USAA reported that call center representatives of a third-party service provider improperly shared USAA access credentials with unauthorized individuals between December 20, 2022, and May 18, 2023. This allowed unauthorized access to personal information of USAA members, including names, addresses, driver's license numbers, last four digits of SSNs, bank account numbers, and authentication PINs. USAA blocked the access and is monitoring accounts. Complimentary identity monitoring services were offered to affected adults and minors.
- Indiana State AGvia NOBLR, INC.2021-05-14
Noblr, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-21 and was reported on 2021-05-14. 223 Indiana residents were affected. 97,633 individuals affected in total.
- New Hampshire State AGvia Noblr Reciprocal Exchange2021-05-10
Noblr Reciprocal Exchange notified the NH Attorney General of a data security event involving unauthorized access to consumer personal information via its public-facing web quotes feature. On January 21, 2021, Noblr detected unusual quote activity and bot traffic intended to scrape driver's license numbers inadvertently included in unredacted page source code. The incident affected at least 65 New Hampshire residents. Noblr masked driver's license numbers and other PII in source code and application pages, blocked suspicious IPs, and adjusted rate limits. Free identity theft protection services were offered.
- Maine State AGvia NOBLR, INC.2021-05-07
Noblr, Inc. experienced an external system breach (hacking) on January 21, 2021, which was discovered on January 27, 2021. The breach affected 97,633 individuals in total, including 68 Maine residents. The compromised information included names in combination with Driver's License or Non-Driver Identification Card Numbers. Noblr offered one year of Experian IdentityWorks identity theft protection services to the affected individuals.
- Massachusetts State AGvia Noblr Reciprocal Exchange2021-05-07
Noblr Reciprocal Exchange reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-05-07. 419 Massachusetts residents were affected. The report records the breach type as electronic.
- Maine State AGvia Noblr Reciprocal Exchange2021-05-07
Noblr Reciprocal Exchange experienced an external system breach (hacking) on January 21, 2021, discovered on January 27, 2021. The incident compromised the names and driver's license numbers of 97,633 individuals, including 68 Maine residents. The entity provided written notification on May 14, 2021, and offered one year of Experian IdentityWorks identity protection services.
- Massachusetts State AGvia USAA Federal Savings Bank2017-04-18
USAA Federal Savings Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-04-18. 2 Massachusetts residents were affected. The report records the breach type as electronic.