CAPITAL ONE SERVICES, LLC
ent_b974418c76bb3b004ea213b3
Disclosures
25+
State AG · 6 jurisdictions
Multi-filing incidents
8
incidents joining 2+ filings here
Max affected reported
140,000
nationwide · State AG DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CAPITAL ONE SERVICES, LLC
- Normalized
- capital one— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300V7U04X9CVH5926
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- capitalone.com
Disclosure history (newest 25)newest first
- Indiana State AGas reporting2026-06-05
Capital Machinery Systems Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2026-05-05 and was reported on 2026-06-05. 140 Indiana residents were affected. 159 individuals affected in total.
- Massachusetts State AGas victim2026-01-28
Capital One notified Massachusetts residents of a data breach affecting US Card account holders. Compromised data included name, address, phone, email, date of birth, credit card numbers, expiration dates, balances, appreciation rates, transaction history, and CVV2 codes. The company offered two years of free credit monitoring via TransUnion. No specific dates for the incident or discovery were provided in the notice.
- Massachusetts State AGas victim2026-01-26
Capital One notified Massachusetts regulators of a technical error where a system integration logic change merged customer profiles, exposing one resident's name, address, email, phone, and bank account number to another customer. No malicious intent or fraud was detected. The affected individual was notified on January 23, 2026, and offered two years of credit monitoring.
- Massachusetts State AGas victim2026-01-23
Capital One notified Massachusetts residents of a data breach affecting bank account information, including name, debit card account number, and CVV2 code. The company offered two years of complimentary credit monitoring via TransUnion. No specific dates for the incident or discovery were provided in the notice.
- Nebraska State AGas victim2025-11-20
Capital One notified the Nebraska Attorney General of a cybersecurity incident involving one Nebraska resident. A now-former service provider employee accessed Capital One US Card customer accounts and attempted unauthorized transactions between May 20, 2025, and July 8, 2025. Capital One discovered the incident on September 2, 2025, and sent a notification letter to the affected resident on November 17, 2025, offering 24 months of free credit monitoring.
- Indiana State AGas victim2025-04-04
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-14 and was reported on 2025-04-04. 1 Indiana residents were affected.
- Massachusetts State AGas victim2025-03-25
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-03-25. 1 Massachusetts residents were affected.
- Massachusetts State AGas victim2025-02-11
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-02-11. 1 Massachusetts residents were affected.
- Delaware State AGas victim2024-08-15
Capital One disclosed a data breach where an individual gained unauthorized access to credit card customer and applicant data between March 22-23, 2019. Capital One determined the breach on July 19, 2019. Approximately 140,000 Social Security numbers and 80,000 bank account numbers were accessed. Capital One fixed the issue, worked with law enforcement, and offered two years of credit monitoring.
- Indiana State AGas victim2024-08-07
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-10-13 and was reported on 2024-08-07. 1 Indiana residents were affected. 13 individuals affected in total.
- Massachusetts State AGas victim2024-03-28
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-03-28. 2 Massachusetts residents were affected.
- Indiana State AGas victim2024-03-26
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-11 and was reported on 2024-03-26. 3 Indiana residents were affected. 23 individuals affected in total.
- Indiana State AGas victim2024-03-26
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-11 and was reported on 2024-03-26. 1 Indiana residents were affected. 23 individuals affected in total.
- Massachusetts State AGas victim2023-11-16
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-11-16. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-06-16
Capital One notified affected individuals that a former employee accessed and attempted unauthorized transactions on credit card accounts between August 11, 2022, and May 22, 2023. The employee no longer has access. Capital One offered two years of free TransUnion credit monitoring.
- Massachusetts State AGas victim2023-06-16
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-16. 4 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-05-26
NCB Management Services, Inc., a third-party accounts receivable provider for Capital One, reported that an unauthorized third party accessed its systems on February 1, 2023, discovered on February 4, 2023. The incident affected 53 New Hampshire residents, exposing names and credit card account information. NCB engaged Kroll for credit monitoring and cooperated with law enforcement.
- Massachusetts State AGas victim2023-05-26
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-26. 164 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2023-05-26
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-02-01 and was reported on 2023-05-26. 403 Indiana residents were affected. 16,779 individuals affected in total.
- Washington State AGas reporting2023-05-26
NCB Management Services, Inc., a third-party accounts receivable provider for Capital One, experienced a security incident where an unauthorized third party accessed systems between Feb 1-4, 2023. The breach exposed names, addresses, SSNs, and account numbers of 605 Washington residents. Capital One Services, LLC filed this notice with the WA AG on May 26, 2023.
- Massachusetts State AGas victim2023-05-02
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-02. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2023-03-21
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-21. 10 Massachusetts residents were affected. The report records the breach type as paper.
- Indiana State AGas victim2023-03-20
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2022-12-27 and was reported on 2023-03-20. 3 Indiana residents were affected. 572 individuals affected in total.
- Massachusetts State AGas victim2023-03-14
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-03-14. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2021-09-17
Capital One reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-09-17. 1 Massachusetts residents were affected. The report records the breach type as electronic.