Publish date
August 5, 2026
{x} minute read
Written by
Reviewed by
Table of contents

These are the 26 largest and most consequential data breaches in financial services, current as of July 2026. They span banks, credit bureaus, payment processors, mortgage servicers, insurers, and the technology vendors that sit behind them, and many of the biggest recent incidents did not start at a bank at all. They started at a third party the customer had never heard of.

Every figure below is drawn from company disclosures, regulator filings, and reputable reporting. Where a count is disputed, estimated, or claimed only by the attacker, it is flagged as such. Before the list, here is the sector context that explains why a bank data breach costs what it does and where the risk is now concentrated.

Sector statistics: financial services breach cost and incident volume

Financial services is one of the most expensive industries to be breached in. The IBM Cost of a Data Breach Report 2025 puts the average financial services breach at USD 5.56 million, second only to healthcare and roughly 25% above the USD 4.44 million global average across all industries. The same report shows the sector's cost easing from USD 6.08 million in the 2024 edition, in line with the first global decline in five years. Any figure labeled as an "IBM 2026" financial-sector number should be treated as unverified until IBM publishes that edition, because several sites relabel 2025 data as 2026.

Cost is only half the picture. The most recent Verizon 2026 Data Breach Investigations Report, built on more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries, found that vulnerability exploitation has overtaken stolen credentials as the leading breach entry point at 31%, and that ransomware now appears in 48% of breaches. The finding that matters most for the entries below is third-party risk: supply chain involvement rose 60% year over year and now features in 48% of breaches. That single trend explains why so many of the largest financial-sector incidents originated with a vendor rather than the institution named in the headline.

26 Biggest Data Breaches in Finance

1. First American Financial Corporation

  • Records affected: approximately 885 million documents exposed. This is a count of documents dating back to 2003, not of individuals, and First American has never published an individual count. Treat any per-person figure as unverified.
  • Date of breach: exposure existed from at least 2003 until May 2019; no evidence of a specific intrusion date.
  • Date disclosed: May 24, 2019, after being reported by KrebsOnSecurity.
  • Country: United States.
  • Sub-sector: title insurance and real estate settlement services.
  • Attack vector: no intrusion. A business logic flaw (an insecure direct object reference) in the EaglePro document-sharing application meant anyone with a valid document link could change the sequential digits in the URL and read any other document without authentication.
  • Data exposed: bank account numbers and statements, mortgage and tax records, wire transaction receipts, Social Security numbers, and driver's license images from real estate closing documents.

This is one of the largest data exposures ever recorded at a financial institution, and it required no hacking skill at all. First American's own penetration test in December 2018 had identified the flaw, and the company did not remediate it before it became public five months later. The exposed documents were exactly the material needed for mortgage wire fraud and identity theft.

Aftermath: the New York Department of Financial Services filed charges in July 2020, the first enforcement action ever brought under the NYDFS Part 500 Cybersecurity Regulation. First American settled with NYDFS in November 2023 for USD 1 million, and separately settled with the SEC in June 2024 for USD 487,616 over disclosure-control failures. A separate December 2023 cyberattack affected around 44,000 individuals.

Source: KrebsOnSecurity | NYDFS | SEC

2. Equifax

  • Individuals affected: 147,900,000 in the United States, plus approximately 15,200,000 UK records and around 19,000 Canadians. The US figure was revised upward twice from an initial 143 million.
  • Date of breach: May 13, 2017 to July 29, 2017, discovered July 29, 2017.
  • Date disclosed: September 7, 2017.
  • Country: United States, with UK and Canadian victims.
  • Sub-sector: consumer credit reporting bureau.
  • Attack vector: exploitation of an unpatched Apache Struts vulnerability (CVE-2017-5638) in the online dispute portal. A patch had been available since March 2017, and an expired TLS inspection certificate meant Equifax could not see the attackers' encrypted exfiltration traffic for 76 days.
  • Data exposed: names, Social Security numbers, dates of birth, addresses, driver's license numbers, around 209,000 payment card numbers, and 182,000 dispute documents containing personal data.

Equifax remains the defining consumer data breach and one of the biggest data breaches in history. The victims were not customers, had no relationship with Equifax, and had never consented to it holding their data, which is what made it politically explosive. Nearly half the US adult population had the identity-verification triad of name, Social Security number, and date of birth stolen at once. Four members of the Chinese People's Liberation Army were indicted for the intrusion in February 2020.

Aftermath: a global settlement with the FTC, CFPB, and 50 US states and territories announced in July 2019 required Equifax to pay at least USD 575 million and up to USD 700 million. The company also agreed to a USD 13.5 million payment with eight state banking regulators, and the UK ICO fined Equifax Ltd GBP 500,000, the maximum under the pre-GDPR Data Protection Act 1998. Equifax committed roughly USD 1.25 billion in incremental technology and security spending, and its CEO, CIO, and CSO all departed.

Source: FTC | US GAO report | ICO fine coverage

3. Heartland Payment Systems

  • Records affected: approximately 130 million payment card numbers.
  • Date of breach: SQL injection foothold established in late 2007, with card-data sniffing running through 2008; discovered January 2009.
  • Date disclosed: January 20, 2009, the day of the US presidential inauguration.
  • Country: United States.
  • Sub-sector: payment processor (then the sixth-largest US card processor, handling around 100 million transactions a month for 175,000 merchants).
  • Attack vector: SQL injection against a web-facing form, then lateral movement to install packet-sniffing malware that captured card data in transit before encryption. Perpetrated by Albert Gonzalez and co-conspirators.
  • Data exposed: payment card magnetic stripe track data, including card numbers, expiration dates, and, for some cards, cardholder names.

Heartland was the largest payment card breach in history when disclosed, and it exposed the central weakness of the PCI DSS regime. Heartland had been certified PCI compliant by a qualified security assessor shortly before the breach. The attackers sat inside for months capturing data in flight, in the one place the standard did not require encryption at the time. The incident drove the industry toward end-to-end encryption, tokenization, and eventually EMV chip adoption in the US.

Aftermath: Heartland disclosed roughly USD 145 million in breach-related expenses, including settlements with Visa, MasterCard, American Express, and Discover, plus fines and legal costs. Albert Gonzalez was sentenced to 20 years in federal prison in March 2010, the longest US sentence for computer crime at the time. Heartland's share price fell by around 80% in the months after disclosure, and the company was later acquired by Global Payments in 2016.

Source: KrebsOnSecurity | US Department of Justice

4. Capital One

  • Individuals affected: approximately 106,000,000 (about 100 million in the United States and 6 million in Canada), including roughly 140,000 US Social Security numbers, 1 million Canadian Social Insurance Numbers, and 80,000 linked bank account numbers.
  • Date of breach: March 22 to 23, 2019, discovered July 19, 2019 after an external tip via a GitHub post.
  • Date disclosed: July 29, 2019.
  • Country: United States and Canada.
  • Sub-sector: consumer and commercial banking, credit cards.
  • Attack vector: a misconfigured open-source web application firewall in Capital One's AWS environment was abused for a server-side request forgery attack against the EC2 instance metadata service, yielding temporary credentials for an over-privileged IAM role that could read S3 buckets.
  • Data exposed: names, addresses, phone numbers, email addresses, dates of birth, self-reported income, credit scores, balances, and payment history, plus the Social Security numbers, Social Insurance Numbers, and bank account numbers noted above, drawn from credit card applications submitted between 2005 and early 2019.

Capital One was the cloud era's first mega-breach at a major bank, and it is the canonical case study for cloud misconfiguration and excessive IAM privilege rather than perimeter failure. The attacker, Paige Thompson, was a former AWS engineer who found the misconfiguration and then posted about the data on GitHub and Slack, which is how Capital One found out. It is the reason instance metadata service v2 and least-privilege IAM review became standard bank audit items.

Aftermath: the Office of the Comptroller of the Currency assessed an USD 80 million civil money penalty in August 2020, and the Federal Reserve issued a cease and desist order. Capital One agreed to a USD 190 million class action settlement in December 2021. Paige Thompson was convicted on seven counts in June 2022 and sentenced in October 2022 to time served plus five years of probation.

Source: OCC | Capital One | US Department of Justice

5. TJX Companies and Global Payments

  • Records affected: 94 million payment cards at TJX, per banks' court filings; TJX itself initially said 45.7 million, so the figure is disputed. Global Payments in 2012 saw approximately 1.5 million card numbers exported, with up to 7 million initially feared.
  • Date of breach: TJX ran July 2005 to December 2006, discovered December 2006. Global Payments ran January to February 2012.
  • Date disclosed: TJX on January 17, 2007. Global Payments on March 30, 2012, after being reported by KrebsOnSecurity.
  • Country: United States (TJX also affected Canada, the UK, and Ireland).
  • Sub-sector: TJX is retail, included here because it is the origin point for the card-breach liability regime that governs payment processors. Global Payments is a payment processor.
  • Attack vector: at TJX, attackers again led by Albert Gonzalez intercepted traffic from poorly secured in-store wireless networks using WEP encryption, then reached the central card processing systems. Global Payments involved an intrusion into the processing environment enabling card data export.
  • Data exposed: TJX exposed card numbers, expiration dates, track data, plus driver's license and Social Security numbers from around 451,000 return records. Global Payments exposed card numbers and track 1 and track 2 data.

TJX was the largest card breach in history until Heartland superseded it, and the same crew ran both. Its lasting significance is legal rather than technical. The settlements TJX reached with Visa and MasterCard established the template by which card networks pass fraud and reissuance costs back through acquirers to breached entities. Global Payments five years later showed the reputational mechanism specific to processors: it was removed from Visa's list of PCI DSS compliant service providers, an existential commercial event for a processor.

Aftermath: TJX disclosed breach costs of approximately USD 256 million, plus a multistate attorney general settlement of USD 9.75 million in 2009 and an FTC consent order requiring 20 years of biennial security audits. Global Payments reported cumulative breach costs of approximately USD 121 million and regained its compliant listing status after remediation.

Source: FTC | KrebsOnSecurity

6. JPMorgan Chase

  • Individuals affected: 76 million households and 7 million small businesses, which the bank described in these terms rather than as an individual count.
  • Date of breach: June 2014 to August 2014, discovered mid-August 2014.
  • Date disclosed: October 2, 2014 via an SEC 8-K.
  • Country: United States.
  • Sub-sector: global systemically important bank.
  • Attack vector: attackers obtained an employee's credentials and used them against a server that had not been upgraded to require two-factor authentication, then moved laterally across more than 90 servers.
  • Data exposed: names, addresses, phone numbers, and email addresses. JPMorgan stated that account numbers, passwords, Social Security numbers, dates of birth, and money were not compromised.

JPMorgan spent roughly USD 250 million a year on cybersecurity at the time and was still breached because a single server in a very large estate had been missed in a two-factor authentication rollout. That is the enduring lesson. In an estate of tens of thousands of servers, coverage gaps rather than attacker sophistication determine outcomes. The scale, roughly two-thirds of US households, made it the largest bank breach disclosed at that point.

Aftermath: no regulatory fine was imposed, largely because no account credentials or financial data were taken. The US Attorney for the Southern District of New York indicted Gery Shalon, Ziv Orenstein, and Joshua Samuel Aaron in November 2015, describing the intrusion as part of a sprawling securities fraud and unlicensed bitcoin exchange enterprise. JPMorgan roughly doubled its annual cybersecurity budget to USD 500 million.

Source: SEC 8-K | US Department of Justice indictment

7. Banco Santander

  • Individuals affected: claimed by the attackers to be 30 million customers in Spain, Chile, and Uruguay, plus all current and some former employees. Santander confirmed a breach affecting customers in those three countries and its staff, but has never confirmed the 30 million figure, which should be treated as an unverified attacker claim.
  • Date of breach: access identified in May 2024, part of the Snowflake-linked campaign running from April 2024.
  • Date disclosed: May 14, 2024.
  • Country: Spain, with affected customers in Chile and Uruguay.
  • Sub-sector: global systemically important bank.
  • Attack vector: unauthorized access to a database hosted by a third-party cloud data warehouse provider. The incident is part of the campaign in which the group UNC5537 used credentials harvested by infostealer malware to log into customer Snowflake tenants that lacked multi-factor authentication.
  • Data exposed: per the ShinyHunters listing, bank account details, credit card numbers, customer names, dates of birth, national ID numbers, and HR information. Santander said no transactional data, online banking credentials, or passwords were accessed.

Santander was one of the highest-profile victims of the 2024 Snowflake campaign, which also hit Ticketmaster, AT&T, Advance Auto Parts, and around 165 other organizations. The vector was not a Snowflake platform vulnerability but customer-side identity failure: valid credentials, no multi-factor authentication, no network restriction. It also ranks among the most significant European data breaches of recent years. For financial services it crystallized the risk of moving large customer datasets into cloud data warehouses without enforcing the identity controls applied to core banking.

Aftermath: Santander notified customers and regulators in the affected markets and said its banking systems and transactions were unaffected. Two suspects linked to the campaign were arrested, including Connor Moucka in Canada in October 2024. Snowflake subsequently made multi-factor authentication enforceable by default. No fine against Santander had been announced as of July 2026.

Source: Reuters | SecurityWeek

8. LoanDepot

  • Individuals affected: 16,924,071.
  • Date of breach: January 3 to 5, 2024, detected January 4, 2024.
  • Date disclosed: SEC 8-K filed January 8, 2024; victim count disclosed January 22, 2024.
  • Country: United States.
  • Sub-sector: non-bank mortgage originator and servicer.
  • Attack vector: ransomware with data exfiltration and system encryption. LoanDepot did not name the group; reporting linked the activity to ALPHV/BlackCat.
  • Data exposed: names, dates of birth, email and postal addresses, financial account numbers, phone numbers, and Social Security numbers.

LoanDepot took systems offline, including its customer portals and phone lines, leaving borrowers unable to make mortgage payments or complete closings for roughly two weeks in the middle of transactions with contractual deadlines. Because mortgage files contain a complete financial profile, from Social Security number to income to bank accounts, non-bank mortgage companies are among the highest-value targets in the sector while typically operating with thinner security programs than regulated depositories.

Aftermath: LoanDepot recorded approximately USD 26.9 million in cyberattack-related expenses in 2024 and disclosed material impacts on origination volume. Consolidated class action litigation in the Central District of California settled for approximately USD 25 million, approved in 2025.

Source: SEC | SecurityWeek

9. Mr. Cooper Group

  • Individuals affected: 14,690,284.
  • Date of breach: October 30 to November 1, 2023, detected October 31, 2023.
  • Date disclosed: incident disclosed November 2, 2023; victim count reported to state attorneys general in December 2023.
  • Country: United States.
  • Sub-sector: mortgage servicer (one of the largest US non-bank servicers), formerly Nationstar Mortgage.
  • Attack vector: unauthorized network access with data exfiltration. Mr. Cooper has not publicly detailed the initial access method.
  • Data exposed: names, addresses, phone numbers, Social Security numbers, dates of birth, and bank account numbers, covering current and former customers whose loans Mr. Cooper serviced.

Mr. Cooper had to take systems offline, which prevented borrowers from making payments during a month-end and quarter-end cycle. The affected population included people who had never chosen Mr. Cooper. Because mortgage servicing rights are bought and sold, the company held records for borrowers whose loans it had acquired, meaning millions of victims had no idea it held their data. Together with LoanDepot two months later, it made US mortgage servicing the most breached corner of financial services in that period.

Aftermath: Mr. Cooper recorded approximately USD 25 million in vendor and remediation costs. More than 20 class actions were consolidated in the Northern District of Texas. No public fine had been announced as of July 2026.

Source: SEC | BleepingComputer

10. Latitude Financial

  • Records affected: approximately 14,000,000 records, including 7.9 million Australian and New Zealand driver's license numbers, roughly 53,000 passport numbers, and 6.1 million records dating back to 2005. This is a record count spanning duplicates, not a distinct individual count.
  • Date of breach: detected March 16, 2023, with escalating disclosures through late March 2023.
  • Date disclosed: March 16, 2023.
  • Country: Australia, also affecting New Zealand customers.
  • Sub-sector: consumer finance, personal loans, and interest-free retail credit.
  • Attack vector: stolen employee login credentials used to access customer data held by two separate service providers.
  • Data exposed: driver's license numbers and copies, passport numbers, names, addresses, dates of birth, and, for some records, monthly financial statements and income information.

Latitude's disclosure escalated dramatically over ten days, from an initial estimate of 328,000 records to 14 million, which severely damaged trust in its incident communications. Because Latitude retained identity documents from credit applications going back to 2005, people who had taken out an interest-free retail finance deal nearly two decades earlier found their license and passport details stolen. Latitude refused to pay the ransom. It is the largest Australian financial-sector breach on record and features in our wider list of the biggest data breaches in Australia.

Aftermath: Latitude reported incident costs of approximately AUD 76 million in its FY2023 results and posted a statutory loss. The Office of the Australian Information Commissioner opened inquiries into the breach, and a class action followed. Arriving months after Optus and Medibank, the breach was a direct driver of Australian government reform on data retention obligations.

Source: OAIC | Reuters

11. Desjardins Group

  • Individuals affected: 9,700,000 (initially reported as 2.9 million members in June 2019, revised to 4.2 million, then to 9.7 million including business members in November 2019).
  • Date of breach: data extracted over approximately 26 months to June 2019.
  • Date disclosed: June 20, 2019.
  • Country: Canada.
  • Sub-sector: cooperative financial group, the largest federation of credit unions in North America.
  • Attack vector: malicious insider. An employee in the marketing department with legitimate access copied member data over more than two years and passed it to third parties.
  • Data exposed: names, dates of birth, Social Insurance Numbers, addresses, phone numbers, email addresses, and details of banking habits and products held. Passwords, PINs, and security questions were not affected.

Desjardins is the largest breach of a Canadian financial institution and the largest insider-driven financial breach in North America. No perimeter was breached and no vulnerability was exploited. An authorized user with legitimate access to member data simply took it, repeatedly, for over two years without triggering any control. It reframed insider risk from a theoretical concern to a board-level one across Canadian financial services.

Aftermath: the Office of the Privacy Commissioner of Canada concluded in December 2020 that Desjardins had contravened PIPEDA. Desjardins reported roughly CAD 108 million in pre-tax costs in 2019 alone and offered all members free credit monitoring. A CAD 200.9 million class action settlement was approved by the Quebec Superior Court in 2021 and 2022, and Quebec's Law 25 privacy reform was shaped in part by this breach.

Source: Office of the Privacy Commissioner of Canada | Reuters

12. Block and Cash App Investing

  • Individuals affected: approximately 8,200,000 current and former Cash App Investing customers.
  • Date of breach: December 10, 2021.
  • Date disclosed: SEC 8-K filed April 4, 2022.
  • Country: United States.
  • Sub-sector: fintech, mobile payments, and retail brokerage.
  • Attack vector: malicious insider. A former employee downloaded internal reports containing customer brokerage information after their employment had ended, using access that had not been revoked.
  • Data exposed: full names, brokerage account numbers, and for some customers brokerage portfolio value, holdings, and stock trading activity for one trading day. Passwords, Social Security numbers, dates of birth, payment card information, addresses, and bank account numbers were not affected.

The vector is the one that recurs across fintech: offboarding failure. A departed employee retained the ability to pull reports on millions of brokerage customers, and Block only found out months later. The exposed data was portfolio holdings and account numbers, precisely the material for targeted social engineering of investors. Block's four-month delay between the December download and the April disclosure drew criticism.

Aftermath: class actions were consolidated. Separately, and not arising from this breach, in January 2025 Block faced two major regulatory actions over Cash App: a coordinated settlement with 48 state financial regulators requiring an USD 80 million penalty, and a CFPB order requiring approximately USD 175 million. These should be read as regulatory findings against Block's controls generally, not as penalties for the 2021 insider breach.

Source: SEC | CFPB

13. Evolve Bank & Trust

  • Individuals affected: 7,640,112.
  • Date of breach: approximately February 7 to May 2024, detected May 29, 2024.
  • Date disclosed: June 26, 2024.
  • Country: United States.
  • Sub-sector: banking-as-a-service sponsor bank, providing the regulated banking layer for fintech companies.
  • Attack vector: LockBit ransomware. Evolve stated that employees clicked on malicious internet links, giving attackers access to customer information in its databases and a backup file. Evolve did not pay the ransom, and LockBit published the stolen data.
  • Data exposed: names, Social Security numbers, dates of birth, account numbers, and other personal information belonging to retail bank customers and to customers of Evolve's fintech partners.

Evolve is the clearest illustration of the sponsor bank problem. It provided the banking rails behind fintechs including Affirm, Wise, Mercury, Bilt, and, notoriously, Yotta via the failed intermediary Synapse, which meant millions of people whose data was stolen had never heard of Evolve. Notification was consequently chaotic, and the breach landed while the bank was already under supervisory pressure.

Aftermath: the Federal Reserve Board issued an enforcement action against Evolve on June 14, 2024, twelve days before the breach became public, citing deficiencies in anti-money laundering, risk management, and consumer compliance in its fintech partnerships. The timing made Evolve the emblem of regulators' broader concerns about banking as a service. Class actions were consolidated in the Western District of Tennessee.

Source: Federal Reserve | SecurityWeek

14. TransUnion

  • Individuals affected: more than 4,400,000 (reported as 4.4 million to 4.5 million in different filings; state attorney general filings give the precise figure).
  • Date of breach: July 28, 2025, discovered July 30, 2025.
  • Date disclosed: late August 2025 via state attorney general notifications.
  • Country: United States.
  • Sub-sector: consumer credit reporting bureau.
  • Attack vector: unauthorized access to a third-party application supporting TransUnion's US consumer support operations, specifically a targeted Salesforce environment. Attributed to the combined Scattered Spider and ShinyHunters activity, which used voice phishing and malicious OAuth-connected apps against Salesforce tenants across hundreds of companies.
  • Data exposed: names, dates of birth, and Social Security numbers. TransUnion stated that no credit reports or core credit information were accessed.

Eight years after Equifax, the second of the big three US bureaus disclosed a breach of the same identity triad, this time not through an unpatched server but through a SaaS CRM instance reached by social engineering. That contrast is the point. The sector hardened its own infrastructure, and the attackers moved to the vendor and identity layer. TransUnion was one of more than 700 organizations caught in the 2025 Salesforce-linked campaign, alongside Allianz Life, Farmers Insurance, Google, Workday, and Qantas.

Aftermath: TransUnion offered 24 months of credit monitoring and identity theft protection, and class actions were filed within days. The incident drew congressional attention to whether credit bureaus should face stricter obligations. No fine had been announced as of July 2026.

Source: SecurityWeek | The Record

15. Prudential Financial

  • Individuals affected: 2,556,210 (revised sharply upward from an initial disclosure of 36,545).
  • Date of breach: February 4 to 5, 2024, detected February 5, 2024.
  • Date disclosed: SEC 8-K filed February 13, 2024; revised victim count filed with the Maine Attorney General in June 2024.
  • Country: United States.
  • Sub-sector: insurance, retirement, and asset management.
  • Attack vector: unauthorized access to Prudential's network by a suspected cybercrime group, with administrative and user data taken from certain systems. The ALPHV/BlackCat ransomware group claimed responsibility.
  • Data exposed: names, addresses, driver's license numbers, and non-driver identification card numbers.

Prudential is the clearest example in the sector of why initial breach figures should never be treated as final. The company's February 8-K described a limited incident affecting 36,545 people. Four months later the count filed with Maine was seventy times larger. Prudential also filed its 8-K within days of the SEC's new four-business-day cyber disclosure rule taking effect, making it one of the earliest tests of that regime.

Aftermath: Prudential offered 24 months of credit monitoring, and class actions were filed in New Jersey. The revision itself became a case study in SEC disclosure practice, since the materiality assessment behind the original 8-K rested on a figure that proved wildly low. No fine had been announced as of July 2026.

Source: SEC | The Record

16. Allianz Life Insurance Company of North America

  • Individuals affected: 1,497,063, per the Office of the Maine Attorney General. Allianz Life initially said the majority of its approximately 1.4 million customers were likely affected.
  • Date of breach: July 16, 2025, discovered July 17, 2025.
  • Date disclosed: July 26, 2025.
  • Country: United States.
  • Sub-sector: life insurance and annuities.
  • Attack vector: social engineering against a third-party, cloud-based CRM system, part of the same Salesforce-targeting campaign by ShinyHunters and Scattered Spider that hit TransUnion. Allianz Life's own systems and network were not breached.
  • Data exposed: names, addresses, dates of birth, and Social Security numbers of customers, financial professionals, and some Allianz Life employees.

Allianz Life was among the first confirmed victims of the 2025 Salesforce vishing campaign, and it notified within ten days, which is unusually quick for the sector. The attackers never touched Allianz Life's infrastructure. The entire loss occurred in a SaaS tenant obtained by phoning a human being. For insurers, which hold beneficiary designations and full identity profiles, this is the highest-consequence version of the vendor-identity problem.

Aftermath: Allianz Life notified the FBI and Minnesota regulators and offered two years of credit monitoring and identity theft restoration. Multiple class actions were filed in the District of Minnesota, and Allianz Life confirmed the breach did not affect Allianz SE's other operating entities. No fine had been announced as of July 2026.

Source: Office of the Maine Attorney General | SecurityWeek

17. Flagstar Bank and the MOVEit campaign

  • Individuals affected: 837,390 Flagstar customers in the MOVEit-related breach. Flagstar's cumulative exposure across three separate breaches in three years exceeds 3.7 million, including approximately 1.5 million in the 2021 Accellion FTA incident and around 1.5 million in a 2022 incident.
  • Date of breach: May to June 2023.
  • Date disclosed: notifications filed November and December 2023.
  • Country: United States.
  • Sub-sector: bank and mortgage servicer.
  • Attack vector: exploitation of the MOVEit Transfer zero-day (CVE-2023-34362) by the Cl0p ransomware group, reaching Flagstar through its service provider Fiserv, which used MOVEit for file transfer on behalf of banking clients.
  • Data exposed: names and Social Security numbers, with additional identifiers for some individuals.

Flagstar is the definitive example of compounding third-party risk in banking: three mass breaches in three years, in 2021 via Accellion FTA, in 2022, and in 2023 via MOVEit through Fiserv, none of which originated in Flagstar's own systems. The broader Cl0p MOVEit campaign is the largest single-vulnerability mass exploitation event on record, affecting more than 2,770 organizations and, by common estimates, over 95 million individuals, with financial services heavily represented.

Aftermath: Flagstar, by then part of New York Community Bancorp, offered credit monitoring and faced class action litigation. Progress Software, MOVEit's vendor, disclosed an SEC investigation and shareholder litigation. The campaign led CISA and the FBI to issue joint advisories on Cl0p and accelerated scrutiny of managed file transfer software across the sector.

Source: Banking Dive | CISA advisory AA23-158A

18. Marquis Software Solutions

  • Individuals affected: up to approximately 1,350,000 customers across 74 or more US financial institutions. The count is aggregated across many notifying banks and credit unions, so the distinct-individual total remains unverified.
  • Date of breach: 2026, with an exploitation window tied to the SonicWall vulnerability campaign.
  • Date disclosed: 2026, through notifications filed by affected financial institutions.
  • Country: United States.
  • Sub-sector: marketing, analytics, and data services vendor to banks and credit unions.
  • Attack vector: exploitation of a SonicWall device vulnerability at the vendor, followed by access to customer datasets held on behalf of financial institution clients.
  • Data exposed: customer personal and account information supplied by financial institutions for marketing and analytics purposes. The precise field list is unverified pending fuller notification detail.

This is the largest financial-sector supply chain breach to emerge in the first half of 2026, and it follows the now-familiar pattern. A mid-sized vendor serving dozens of small and mid-sized institutions is compromised through an edge security appliance, and the aggregate victim count dwarfs anything those individual banks would have suffered alone. Because each institution notifies separately, the incident is systematically under-counted in breach trackers.

Aftermath: notifications and credit monitoring were offered by the individual financial institutions. Given the number of affected regulated entities, examination-level scrutiny from the OCC, FDIC, and NCUA is likely. Regulatory and litigation outcomes were not known as of July 2026, and details beyond the affected-institution count should be treated as provisional.

Source: Corbado | Tech.co

19. Heritage Bank

  • Individuals affected: 182,793.
  • Date of breach: March to April 2026.
  • Date disclosed: 2026.
  • Country: United States.
  • Sub-sector: regional bank.
  • Attack vector: unauthorized network access with data exfiltration. The method is unverified pending fuller disclosure.
  • Data exposed: customer personal information. The precise field list is unverified pending fuller notification detail.

This is one of the larger single-institution US bank breaches confirmed in the first half of 2026. At roughly 183,000 individuals it is modest by the standards of the entries above, which is itself informative. The very large 2026 financial-sector numbers came from vendors, not from banks' own networks. Details remain thin and should be checked against the bank's own notice and state attorney general filings before publication.

Aftermath: notifications were issued and credit monitoring offered. No regulatory action or litigation outcome was known as of July 2026.

Source: Tech.co | Corbado

20. Fidelity Investments

  • Individuals affected: 77,099 in the August 2024 incident. Separately, 28,268 Fidelity Investments Life Insurance Company customers were affected via the Infosys McCamish breach.
  • Date of breach: August 17 to 19, 2024, detected August 19, 2024.
  • Date disclosed: October 9, 2024 via a Maine Attorney General filing.
  • Country: United States.
  • Sub-sector: asset management and retail brokerage.
  • Attack vector: a third party accessed customer information by using two newly established customer accounts. In effect, the attacker enrolled as a customer and then abused the resulting access to retrieve documents relating to other customers.
  • Data exposed: names and other personal information, including Social Security numbers and driver's license numbers. Fidelity said no customer accounts were accessed and no funds were affected.

The vector here is distinctive and under-appreciated: no vulnerability, no phishing, no vendor. The attacker legitimately signed up, then exploited a flaw in how the platform scoped document access for authenticated users. Any financial platform with self-service onboarding and document retrieval carries this risk, and patching or multi-factor authentication will not catch it. Fidelity administers roughly USD 14 trillion in assets, so even a five-figure victim count is significant.

Aftermath: Fidelity offered 24 months of credit monitoring and identity restoration through TransUnion, and class actions were filed in Massachusetts. Fidelity closed the two fraudulent accounts and said it had remediated the access issue. No fine had been announced as of July 2026.

Source: Office of the Maine Attorney General | TechCrunch

21. Truist Financial

  • Individuals affected: the threat actor Sp1d3r advertised data on approximately 65,000 employees, alongside bank transaction data and source code for an internal IVR funds transfer system. Truist confirmed a breach dating to October 2023 but has not confirmed the 65,000 figure or the contents, so the count is an unverified attacker claim.
  • Date of breach: October 2023.
  • Date disclosed: June 2024, after data was offered for sale on a cybercrime forum.
  • Country: United States.
  • Sub-sector: bank holding company, one of the largest US commercial banks, formed by the BB&T and SunTrust merger.
  • Attack vector: not publicly confirmed. Truist said it contained the October 2023 incident at the time and that the data offered for sale related to that event. Some reporting linked Sp1d3r's activity to the Snowflake campaign, though Truist did not confirm a Snowflake connection.
  • Data exposed: per the seller's listing, employee names, dates of birth, Social Security numbers, salary, and bank account numbers, plus bank transaction records and IVR source code. Truist said no customer data was included in what it verified.

Truist's significance is disclosure practice rather than scale. The bank had detected and contained an incident in October 2023, believed it resolved, then found the data for sale publicly eight months later. That gap between containment and discovery of exfiltration is common and rarely acknowledged. The alleged inclusion of IVR funds-transfer source code, if accurate, would matter more than the employee records, since it maps a live payment authorization path. This entry should be read as attributed to the seller's claims rather than confirmed fact.

Aftermath: Truist said it had hardened the affected systems and that the incident did not involve customer accounts. Given the disputed contents, no confirmed victim notification program of scale was made public, and no regulatory action had been announced as of July 2026.

Source: American Banker

22. Bank of America, via Infosys McCamish Systems

  • Individuals affected: 57,028 Bank of America deferred compensation plan participants. The Infosys McCamish incident affected more than 6,500,000 individuals in total across all its financial services clients (revised upward from an initial 57,028 and then from roughly 6.08 million).
  • Date of breach: October 29 to November 2, 2023 at Infosys McCamish Systems.
  • Date disclosed: Bank of America notified affected individuals in February 2024 via a Maine Attorney General filing; Infosys McCamish's full victim count was reported in June 2024.
  • Country: United States.
  • Sub-sector: insurance and retirement plan administration outsourcing.
  • Attack vector: ransomware at Infosys McCamish Systems, a subsidiary of Infosys BPM. LockBit claimed responsibility, and approximately 2,180 systems were affected.
  • Data exposed: names, addresses, business email addresses, dates of birth, Social Security numbers, account numbers, and, for some individuals, credit card numbers and other financial account information.

Bank of America itself was never breached. Its customers' data was exposed because a vendor's subsidiary was hit, and Bank of America was only one of dozens of downstream clients that also included Fidelity Investments Life Insurance, Union Labor Life, and Oceanview Life and Annuity. This is the archetypal financial services fourth-party incident, and the reason vendor concentration in insurance and retirement plan administration is now a named supervisory concern.

Aftermath: Infosys McCamish agreed to a class action settlement of approximately USD 17.5 million, approved in 2025, covering the full 6.5 million affected population. Bank of America offered affected participants 24 months of identity theft protection, and multiple state attorneys general reviewed the notification timeline, which ran several months behind the incident.

Source: Office of the Maine Attorney General | BleepingComputer

23. Ameriprise Financial

  • Individuals affected: up to 47,876.
  • Date of breach: March 2026.
  • Date disclosed: 2026, via notification to the Oregon Department of Justice.
  • Country: United States.
  • Sub-sector: wealth management, financial planning, and asset management.
  • Attack vector: unauthorized access with data exfiltration. The method is unverified pending fuller disclosure.
  • Data exposed: client personal information. The precise field list is unverified pending fuller notification detail.

This is a confirmed first-half 2026 breach at a major US wealth manager, disclosed through state attorney general channels rather than a headline announcement, which is how most mid-scale financial breaches now surface. The count is modest, but the population matters. High-net-worth wealth management clients are prime targets for subsequent social engineering and account takeover, so the downstream fraud value per record is far above average.

Aftermath: notifications were issued and credit monitoring offered. No regulatory action or litigation outcome was known as of July 2026, and the figures should be verified against the Oregon DOJ and other state filings before publication.

Source: Tech.co | Oregon Department of Justice

24. Western Alliance Bank

  • Individuals affected: 21,899.
  • Date of breach: October 12 to 24, 2024, with the vulnerability exploited from around October 9, 2024.
  • Date disclosed: February 2025, via an SEC filing and state attorney general notifications.
  • Country: United States.
  • Sub-sector: commercial bank.
  • Attack vector: exploitation of a zero-day vulnerability in the Cleo Harmony, VLTrader, and LexiCom managed file transfer software (CVE-2024-50623 and the related CVE-2024-55956) used by a third-party vendor. The Clop ransomware group claimed the campaign and listed Western Alliance among its victims.
  • Data exposed: names, Social Security numbers, dates of birth, financial account numbers, driver's license numbers, tax identification numbers, and passport or other government ID numbers.

The affected count is small, but the case matters because it is the third generation of the same attack pattern in the sector. Clop exploited Accellion FTA in 2021, MOVEit Transfer in 2023, and Cleo in late 2024, each time hitting financial institutions through vendors that used managed file transfer software to move bulk customer files. Western Alliance also disclosed the incident in an SEC filing under the cyber disclosure rule, giving a clean public record of a Cleo-campaign victim in banking.

Aftermath: Western Alliance offered credit monitoring and identity protection and stated the incident did not have a material impact on operations. Cleo issued patches, CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, and class action litigation was filed.

Source: SecurityWeek | CISA Known Exploited Vulnerabilities catalog

25. Finastra

  • Individuals affected: not quantified. Finastra has not published a victim count, and it is unclear whether consumer personal data was involved. The threat actor claimed approximately 400 GB of data. Treat all volume claims as unverified.
  • Date of breach: detected November 7, 2024.
  • Date disclosed: November 19, 2024, after being reported by KrebsOnSecurity following internal notifications to clients.
  • Country: United Kingdom and United States (Finastra is headquartered in London with major US operations).
  • Sub-sector: financial technology provider of core banking, payments, lending, and treasury software.
  • Attack vector: compromised credentials used to access an internally hosted secure file transfer platform used to exchange files with clients. Finastra said the platform was not the one used for its main product suites.
  • Data exposed: client files transferred through the file transfer platform. Because Finastra's clients are banks, the material is understood to relate to institutional file exchange rather than a single consumer database.

Finastra serves more than 8,000 financial institutions, including 45 of the world's top 50 banks, which makes it one of the highest-consequence single points of failure in global finance. For more incidents affecting UK-headquartered organizations, see the biggest data breaches in the UK. The breach's importance is not the record count, which was never established, but the demonstration that a core banking software vendor's file exchange infrastructure can be entered with stolen credentials. A threat actor using the handle abyss0 offered the data for sale before withdrawing the listing.

Aftermath: Finastra notified affected clients directly and engaged a third-party forensics firm, and said the incident was contained to the file transfer platform. Because its counterparties are institutions rather than consumers, no mass consumer notification followed. This entry is included for systemic significance rather than scale.

Source: KrebsOnSecurity | Infosecurity Magazine

26. American Express, via a third-party merchant processor

  • Individuals affected: not disclosed. American Express has never published a count for the March 2024 third-party processor incident. Any circulating figure is unverified.
  • Date of breach: not specified by American Express.
  • Date disclosed: March 2024, via notification to the Massachusetts Attorney General and letters to affected card members.
  • Country: United States.
  • Sub-sector: card issuer and payment network.
  • Attack vector: unauthorized access to a merchant processor's system. The breach occurred at a third-party service provider used by merchants that accept American Express cards, not at American Express itself.
  • Data exposed: American Express card account numbers, card member names, and card expiration dates.

American Express's notice was explicit that its own systems were not compromised and that the exposure arose at a merchant processor, which is why it could not name a single accountable entity to consumers. The absence of any published victim count is itself notable. Card issuers routinely reissue cards after processor breaches without ever quantifying exposure publicly, which means processor breaches are systematically invisible in breach statistics. This entry is presented with the count explicitly marked as undisclosed.

Aftermath: American Express advised affected card members to review statements and enable transaction alerts, and issued replacement cards where warranted. Because card network rules place fraud liability on issuers and acquirers rather than consumers, direct consumer harm was limited to reissuance friction. No regulatory action against American Express followed.

Source: BleepingComputer | Massachusetts Attorney General

H1 2026 financial services incidents: what is confirmed so far

Three first-half 2026 incidents appear above as ranked entries: Marquis Software Solutions (up to approximately 1.35 million customers across 74 or more US financial institutions, via a SonicWall vulnerability), Heritage Bank (182,793 individuals, March to April 2026), and Ameriprise Financial (up to 47,876 individuals, March 2026). The pattern in the first half of 2026 mirrors 2024 and 2025 rather than departing from it:

  • The largest counts came from vendors, not banks. The single biggest financial-sector figure of the period belongs to a marketing and analytics supplier, not to any regulated institution, matching the Verizon 2026 DBIR finding that third-party involvement now features in 48% of breaches.
  • Edge security appliances remained the entry point of choice. The Marquis incident stems from the SonicWall exploitation campaign, continuing the sequence that ran through Accellion, Fortra GoAnywhere, MOVEit, and Cleo, and matching the DBIR finding that vulnerability exploitation is now the leading breach vector at 31%.
  • Disclosure increasingly surfaces through state channels first. Both Heritage Bank and Ameriprise became public through state attorney general and state DOJ filings rather than company announcements, which is where refresh research should be pointed.

One caveat carries real weight here. First-half 2026 financial-sector figures are provisional, and counts in vendor-originated incidents are routinely revised upward months later, as Conduent, Prudential, and Infosys McCamish all demonstrate.

How UpGuard helps monitor bank and third-party breach risk

The throughline across these 26 incidents is that the largest recent breaches are vendor-originated and identity-driven, and the vendor is usually invisible to the affected customer. Managing that risk, and learning how to prevent third-party data breaches, means watching your own attack surface, your vendors, and your workforce at the same time. That is where UpGuard focuses:

  • Breach Risk provides external attack surface management, dark web exposure monitoring, and threat intelligence in a single view, and prioritizes findings using exploitation probability and known exploited vulnerabilities rather than raw severity scores alone.
  • Vendor Risk supports continuous third-party monitoring, security ratings, and questionnaire management, which addresses the supply chain vector behind incidents like Marquis, the MOVEit campaign, and the Infosys McCamish exposure.
  • User Risk discovers workforce risks such as compromised credentials and coaches users in the moment, relevant to the infostealer and voice-phishing vectors behind the Santander, TransUnion, and Allianz Life incidents.

Continuous monitoring across all three surfaces is what turns a reactive notification process into an early warning system, and it underpins any serious effort to reduce the risk of data breaches. To see how it works on your own environment, start a free trial.

Frequently asked questions

Which banks have recently been hacked?

Recent confirmed financial-services incidents include TransUnion and Allianz Life, both breached through the 2025 Salesforce social-engineering campaign, and the 2026 Marquis Software Solutions and Heritage Bank incidents. Many of these reached the institution through a third-party system rather than its core banking network.

What is the largest financial data breach?

First American Financial Corporation's exposure of approximately 885 million documents is the largest financial-sector data exposure on record, though that is a count of documents dating back to 2003, not a count of individuals.

Are recent bank breaches caused by the banks themselves?

Increasingly, no. The Verizon 2026 Data Breach Investigations Report found that third-party involvement now features in 48% of breaches, and several of the largest financial-sector incidents originated at a vendor rather than the named institution.

How can I check if my data was exposed in a bank breach?

Watch for breach-notification letters and check your state attorney general's data breach filings, monitor your account statements for unfamiliar activity, and enroll in any official credit-monitoring offer provided after an incident.