Comerica Bank
ent_be923e1a8ab8d6b8d46326f6
Disclosures
5
State AG · 4 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
347
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Comerica Bank
- Normalized
- comerica bank— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 70WY0ID1N53Q4254VH70
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- Nebraska State AGas victim2025-08-20
Comerica Bank notified Nebraska residents of a privacy event involving its Direct Express debit card program. Between March and May 2025, a vendor employee engaged in fraudulent activity, potentially accessing cardholders' names, addresses, phone numbers, financial info, DOB, and SSNs. Comerica offered 12 months of free identity theft protection via Equifax.
- Massachusetts State AGas victim2023-08-23
Comerica Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-23. 80 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas reporting2023-08-23
Pension Benefit Information, LLC (PBI) disclosed a third-party software event involving the MOVEit Transfer vulnerability exploited by an unauthorized third party. Access occurred May 29-30, 2023. Data involved names and other data elements. PBI offered credit monitoring via Kroll.
- Massachusetts State AGas victim2012-08-01
Comerica Bank reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-08-01. 347 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2012-07-30
Comerica Bank reported a security incident involving unauthorized access to merchant application data hosted by third-party processor Global Payments, Inc. The breach potentially exposed personal information from merchant applications, including names, Social Security numbers, and business bank account numbers. The incident was discovered in June 2024. Comerica notified affected individuals, offering one year of free credit monitoring and identity protection services through Equifax. The investigation into whether data was actually exfiltrated was ongoing at the time of notification.