A Chase employee improperly downloaded customer information, including names, addresses, mortgage loan numbers, and Social Security numbers, to a personal computer and two online data storage sites on or around June 28, 2018. The data remained accessible to third parties for approximately three weeks. The employee was authorized to access the data but violated policy by using unapproved devices and sites. Chase deleted the data from the unauthorized locations and offered two years of free credit monitoring.