Confirmed breach. Intrusion Jul 30, 2020, discovered Aug 21, 2020 — the first regulatory filing landed 28 days later. 14,112 individuals reported across the linked filings.
U.S. Bank, N.A. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-09-18. The breach occurred during 7/30/2020 - 7/30/2020. The breach was discovered on 8/21/2020. 14,108 individuals were affected. Notice was sent on 9/18/2020.
Affected (this filing):
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
14,108
OR AG ≤45d
🦞Maine State AGlinked via multistate filing link · 100%
U.S. Bank, N.A. reported a data breach involving the loss or theft of a device or media, such as a computer, laptop, or external hard drive. The breach occurred on July 30, 2020, and was discovered on August 21, 2020. The compromised information includes names and financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. Four Maine residents were affected by this incident.
Affected (this filing): 4
ME AG ≤30d · 28d
🐻California State AGlinked via multistate filing link · 100%
U.S. Bank, N.A. reported the physical theft of a computer server from a corporate office on July 30, 2020. The server contained personally identifiable information, including names and account numbers. The bank is working with authorities to recover the server and offering affected customers new account numbers. No fraudulent use was known at the time of notification.