Bank of America Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do
Bank of America has issued a data-breach notice, filed with the Massachusetts Attorney General and dated June 15, 2026, stating that one individual’s Social Security number and financial account numbers were exposed. Customers are advised to review the notice and take appropriate steps if their information may have been affected.
Bank of America notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on June 15, 2026. Public detail in that notice states that Social Security numbers and financial account numbers were among the information exposed, and that one person was affected.
Even when the reported scale is limited to a single individual, exposure of those data types matters because they can be reused in identity theft and account fraud. Beyond the filing itself, public detail on timing of the underlying incident, how it occurred, and broader scope remains limited.
What happened
According to the breach notice associated with the Massachusetts Attorney General / Office of Consumer Affairs reporting channel, Bank of America advised of a data breach in a filing dated June 15, 2026. The notice lists Social Security numbers and financial account numbers among the information exposed and reports one person affected.
The available record does not describe the technical method of intrusion or error, the date range of unauthorized access or exposure, whether systems were encrypted, or whether other categories of information were involved. It also does not attribute the incident to a named threat group. Those elements are undisclosed in the facts provided.
How a breach like this happens
Incidents that lead banks to notify regulators and individuals typically fall into a few broad patterns. Attackers may obtain valid credentials through phishing or stolen passwords and then access customer-support or account systems. Malware on an employee or vendor device can lead to theft of files or database extracts. Misconfigured cloud storage, email sent to the wrong recipient, or a compromised third-party service provider can also expose records without a dramatic network intrusion.
In other cases, an insider misuses legitimate access, or a laptop or backup media is lost. Once Social Security numbers and account numbers leave controlled systems, they may be sold, used for synthetic identity applications, or combined with other public data. None of these general patterns is confirmed for this specific Bank of America notice; they are background on how similar events often unfold when method is not publicly detailed.
Bank of America and its sector
Bank of America is a major U.S. financial institution that provides retail banking, credit cards, lending, wealth management, and related services to consumers and businesses. Organizations in this sector routinely maintain identity data needed to open and service accounts, including government identifiers, account and routing numbers, transaction history, contact details, and authentication records.
A breach notice from a large bank is consequential because financial institutions sit at the center of payments and credit. Even a filing that reports a small number of affected people can prompt scrutiny from state consumer-protection offices and can leave the named individual with lasting monitoring burdens. Confidence in account security also affects how customers interact with digital banking channels across the industry.
What data was at risk
The Massachusetts-related notice names the following as among the information exposed:
- Social Security numbers
- Financial account numbers
The filing reports one person affected. Exact additional fields, full account profiles, or whether other data elements were involved are not described in the provided facts. Banks of this type typically also hold names, addresses, dates of birth, online-banking credentials, and transaction records, but those categories should not be treated as confirmed exposures in this incident unless a later official notice says so.
What's at stake
For the affected person, a Social Security number combined with financial account numbers can support attempts to open new credit, file fraudulent tax returns, take over existing accounts, or socially engineer call centers. Remediation often requires extended credit freezes, fraud alerts, and careful review of statements—work that can continue long after the initial notice.
For the institution, consequences can include regulatory follow-up, notification and support costs, and reputational pressure to demonstrate stronger controls. Because only one person is reported affected in this filing, organizational impact may be narrower than in mass breaches, but the sensitivity of the named data types remains high for that individual. Public detail does not establish negligence or assign fault; it records that a notice was filed and what categories were listed.
What to do if you're exposed
If you believe you are the individual referenced in this notice, or if Bank of America has contacted you directly, treat the named data types as compromised for practical purposes. Place a fraud alert or credit freeze with the major credit bureaus, monitor bank and credit-card statements closely, and change online-banking passwords and multi-factor authentication settings on any related accounts. Consider requesting a new account number if your financial institution advises it. Keep copies of any official notice you receive and use only contact channels you initiate from known bank websites or statements, not from unsolicited messages.
Readers who want a broader check can run a free exposure scan of their email address to see whether their information has appeared in known breach datasets, then follow up with credit monitoring and account reviews as needed. Official guidance from your bank and from state consumer agencies should take priority over informal advice whenever the two differ.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Spectrum Laboratory Products, Inc. Data Breach Notice (Massachusetts Attorney General)Murfreesboro Medical Clinic Data Breach Notice (Massachusetts Attorney General)Healthfirst Bluegrass, Inc. Data Breach Notice (Massachusetts Attorney General)The Health Trust and its subsidiary, FASS Data Breach Notice (Massachusetts Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.