LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › TD Bank U.S. Data Breach Notice (Massachusetts Attorney General)

CRITICAL severityConfirmedHow we verify

TD Bank U.S. Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 15, 2026
TD Bank U.S. Data Breach Notice (Massachusetts Attorney General)

Reported June 15, 2026. Approximately 2 people affected.

CRITICAL
Severity
2
People affected
4
Data types exposed
June 15, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

TD Bank U.S. has disclosed a data breach affecting two individuals, exposing Social Security numbers, financial account numbers, driver’s license numbers, and credit or debit card numbers. The notice was filed with the Massachusetts Attorney General on June 15, 2026; affected individuals should verify their status and take protective steps.

Severity & verification
CRITICAL severityConfirmed
Exposes government-ID/financial data.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
2 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

A small number of people may have had highly sensitive personal and financial details exposed in a data incident involving TD Bank U.S. Public notice of the event was filed in Massachusetts, and the information named in that notice includes identifiers that can be used for identity theft and account fraud. Even when the reported count of affected individuals is low, the types of data involved raise practical stakes for anyone who receives a notice or who banks with the institution and wants to understand what was disclosed.

According to the filing reported on June 15, 2026, TD Bank U.S. notified Massachusetts residents of a data breach. The notice lists Social Security numbers, financial account numbers, driver’s license numbers, and credit or debit card numbers among the information exposed. Two people are reported as affected. Broader technical detail about how the incident occurred has not been set out in the facts available from that disclosure.

What happened

TD Bank U.S. submitted a data breach notice that was reported to the Massachusetts Office of Consumer Affairs on June 15, 2026, in connection with notification to Massachusetts residents. The disclosure is associated with the Massachusetts Attorney General’s breach-notice context. The reported number of people affected is 2.

The notice names the following categories of information as exposed: Social Security numbers, financial account numbers, driver’s license numbers, and credit or debit card numbers. Public detail in the provided record does not describe the intrusion method, the systems involved, the duration of unauthorized access, whether data was exfiltrated in bulk or viewed in limited form, or any dollar loss. Timing of discovery and containment beyond the June 15, 2026 reporting date is undisclosed in the facts given here.

How a breach like this happens

In general terms, incidents that lead banks to notify customers about exposed identity and account data often begin with unauthorized access to systems that store customer records, employee tools, or third-party service environments. Typical pathways discussed in the security field include compromised credentials, phishing that yields access to internal applications, misconfigured remote access, malware on endpoints that handle customer files, or weaknesses in vendor connections that process or store the same kinds of fields banks must keep for compliance and operations.

Once access is obtained, attackers or unauthorized parties may search for files, databases, or exports that contain government identifiers, account numbers, and payment card data. Not every incident involves a large-scale dump; some affect a narrow set of records tied to specific accounts or support cases. Organizations then investigate, determine whose information was involved, and issue notices required by state law when certain data elements are implicated. No specific threat group is attributed in the facts for this TD Bank U.S. matter, and none should be assumed.

TD Bank U.S. and its sector

TD Bank U.S. operates as a retail and commercial banking organization in the United States, part of the broader banking sector that holds deposits, extends credit, and processes payments. Institutions of this kind routinely maintain customer identity information, account numbers, transaction history, and records needed for lending, fraud prevention, and regulatory compliance. Driver’s license and Social Security number data often appear in account-opening, credit, and identity-verification workflows. Payment card numbers appear in debit and credit products and related servicing.

A breach notice from a bank is consequential because the same data set that enables everyday banking can also enable impersonation, new-account fraud, and unauthorized transactions if it reaches the wrong hands. Even a filing that reports only two affected individuals underscores that banking records are high-value targets and that state notification regimes treat certain combinations of identifiers as warranting formal consumer notice.

The information in question

The Massachusetts-related notice explicitly lists Social Security numbers, financial account numbers, driver’s license numbers, and credit or debit card numbers as among the information exposed. Those categories are confirmed by the disclosure summary. The facts do not further break down which combination applied to each of the two people, whether full or partial numbers were involved, or whether additional unlisted fields were present.

Organizations in banking typically also hold names, addresses, contact details, and authentication-related data; whether any of those appeared in this incident is unconfirmed in the provided record. Readers should rely on the individual notice they receive from the bank for the precise elements tied to their own situation rather than assuming a full customer-file exposure.

What's at stake

For affected people, the concrete risks center on identity theft and financial fraud. Social Security numbers can be misused in attempts to open credit, file false claims, or pass identity checks. Driver’s license numbers can support impersonation in contexts that accept government ID details. Financial account numbers and credit or debit card numbers can be used in unauthorized payment or account-takeover attempts, depending on what other authenticators an attacker can obtain or bypass.

For the organization, stakes include regulatory notification duties, customer trust, fraud-monitoring costs, and the operational work of investigation and remediation. The reported scale—two people—limits the breadth of direct consumer impact described in the filing, but it does not reduce the sensitivity of the data types named. Public detail does not establish negligence or assign root-cause fault; those determinations are outside the facts given here.

If your data was in this breach

If you receive a notice from TD Bank U.S., or if you believe you may be one of the individuals referenced in the Massachusetts filing, practical first steps focus on monitoring and locking down high-risk channels rather than panic. Consider the following:

You can also run a free exposure scan of your email address to check whether your information has surfaced in known breach data sets elsewhere. That kind of check does not replace the bank’s official notice, but it can help you see whether the same address appears in other publicly tracked incidents and prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyTD Bank U.S. security record
5/100
DoxxScan™ · Severe doxx risk
D- 44Very poor record

4 reported incidents on record.

See TD Bank U.S.’s full breach history →
RelatedMore incidents at TD Bank U.S.

More recent breaches

Healthfirst Bluegrass, Inc. Data Breach Notice (Massachusetts Attorney General)August 27, 2026Spectrum Laboratory Products, Inc. Data Breach Notice (Massachusetts Attorney General)August 27, 2026Murfreesboro Medical Clinic Data Breach Notice (Massachusetts Attorney General)August 27, 2026Castle Management, LLC Data Breach Notice (Massachusetts Attorney General)August 26, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the TD Bank U.S. Data Breach Notice (Massachusetts Attorney General) →

Source: Massachusetts Office of Consumer Affairs breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram