Capital One
ent_b974418c76bb3b004ea213b3
Disclosures
18
State AG · 7 jurisdictions
Incidents
4
filings grouped by incident
Max affected reported
1,000,000
nationwide · State AG DE
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Capital One
- Normalized
- capital one— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- capitalone.com
Disclosure history (18)newest first
- 🏎️Indiana State AGas victim2026-06-05
Capital Machinery Systems Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2026-05-05 and was reported on 2026-06-05. 140 Indiana residents were affected. 159 individuals affected in total.
- 🏎️Indiana State AGas victim2025-04-04
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-14 and was reported on 2025-04-04. 1 Indiana residents were affected.
- 🏎️Indiana State AGas victim2024-08-07
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-10-13 and was reported on 2024-08-07. 1 Indiana residents were affected. 13 individuals affected in total.
- 🏎️Indiana State AGas victim2024-03-26
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-11 and was reported on 2024-03-26. 3 Indiana residents were affected. 23 individuals affected in total.
- 🏎️Indiana State AGas victim2024-03-26
Capital One reported a data breach to the Indiana Attorney General. The breach occurred on 2023-06-11 and was reported on 2024-03-26. 1 Indiana residents were affected. 23 individuals affected in total.
- ⛰️New Hampshire State AGas reporting2023-08-23
Capital Formation Group experienced a phishing incident involving an employee's email account. Unauthorized access occurred between February 8 and 14, 2023. The company discovered the activity on February 14, 2023, and began notifying affected individuals on July 27, 2023. The breach affected approximately 4 New Hampshire residents, involving personal information such as names and addresses. The company reported the incident to law enforcement, provided credit monitoring via Experian, and secured its email environment.
- 🍁Vermont State AGas reporting2023-07-27
Capital Formation Group notified consumers of a data breach involving unauthorized access to an employee email account between Feb 8-14, 2023. The incident likely exposed names and contact information. The company reported the incident to law enforcement and offered 24 months of credit monitoring via Experian. Notification was sent July 27, 2023.
- ⛰️New Hampshire State AGas reporting2023-07-27
Capital Formation Group notified New Hampshire residents of a phishing incident where an employee's email account was compromised between Feb 8-14, 2023. The company reported to law enforcement, offered credit monitoring via Experian, and enhanced email security. One NH resident was affected.
- ⛰️New Hampshire State AGas victim2023-06-16
Capital One notified affected individuals that a former employee accessed and attempted unauthorized transactions on credit card accounts between August 11, 2022, and May 22, 2023. The employee no longer has access. Capital One offered two years of free TransUnion credit monitoring.
- ⛰️New Hampshire State AGas reporting2023-05-26
NCB Management Services, Inc., a third-party accounts receivable provider for Capital One, reported that an unauthorized third party accessed its systems on February 1, 2023, discovered on February 4, 2023. The incident affected 53 New Hampshire residents, exposing names and credit card account information. NCB engaged Kroll for credit monitoring and cooperated with law enforcement.
- 🦞Maine State AGas victim2021-03-31
Capital One, National Association reported a cybersecurity incident to the Maine Attorney General. The breach occurred on November 10, 2020, and was discovered on March 23, 2021. A total of 426 individuals were affected, including 2 Maine residents. The incident involved the potential acquisition of names and financial account numbers (in combination with security codes or PINs). Capital One stated there is no evidence that data was actually breached but issued notifications as an abundance of caution. Affected individuals were offered 24 months of credit monitoring via TransUnion.
- 🐻California State AGas victim2021-03-26
Capital One reported a data breach occurring on March 22-23, 2019, involving unauthorized access to customer information. The incident involved an exploit of a public-facing application. Affected data types include PII, identity information, and financial account data. Capital One resolved the issue immediately, cooperated with federal authorities, and offered two years of credit monitoring to affected individuals.
- 🐻California State AGas victim2019-09-11
Capital One filed a supplemental breach notification with the California AG regarding unauthorized access to its network on March 22-23, 2019. An external individual exploited a vulnerability to access consumer and small business application data (names, addresses, DOBs, income) and some transaction data. Approximately 25,850 California residents had SSNs and bank account numbers exposed. Capital One fixed the vulnerability, notified law enforcement, and provided two years of credit monitoring to affected residents.
- 🐻California State AGas victim2019-08-12
Capital One notified the California AG of a breach occurring March 22-23, 2019, discovered July 19, 2019. An external individual exploited a vulnerability to access credit card applicant and customer data, including names, SSNs, and bank account numbers. 17,807 California residents were notified. Capital One fixed the vulnerability, worked with law enforcement, and provided two years of credit monitoring via TransUnion.
- 💎Delaware State AGas victim2019-08-08
Capital One notified Delaware AG (Case DSE 191404) of a data breach occurring March 22-23, 2019, discovered July 19, 2019. An external individual gained unauthorized access to credit card application and customer data from 2005-2019. Approximately 1 million individuals affected, including 140,000 SSNs and 80,000 bank account numbers. Capital One offered 2 years of TransUnion credit monitoring and worked with federal law enforcement.
- 🐻California State AGas victim2018-08-09
A former Capital One employee accessed Capital One 360 customer account information without authorization between January 27, 2017 and April 20, 2017. Exposed data included names, addresses, account numbers, phone numbers, transaction history, dates of birth, and Social Security Numbers. A total of 586 California residents were notified in two waves (July and September 2017). The employee was terminated. Capital One notified the California AG in August 2018.
- 🦬Montana State AGas reporting2017-09-12
Capital One 360 reported a data breach to the Montana Attorney General. The breach was reported on 2017-09-12. The breach occurred from 1/27/2017 to 4/20/2017. 4 Montana residents were affected.
- 🐻California State AGas victim2017-02-06
Capital One notified California residents that fraudsters used stolen credentials from third-party websites to access Capital One accounts. The breach involved unauthorized login attempts using valid usernames and passwords. Affected data included names, addresses, and partial account numbers. Capital One locked affected accounts, required password resets, and provided two years of free credit monitoring via TransUnion.