These are the 26 largest and most consequential data breaches in financial services, current as of July 2026. They span banks, credit bureaus, payment processors, mortgage servicers, insurers, and the technology vendors that sit behind them, and many of the biggest recent incidents did not start at a bank at all. They started at a third party the customer had never heard of.
Every figure below is drawn from company disclosures, regulator filings, and reputable reporting. Where a count is disputed, estimated, or claimed only by the attacker, it is flagged as such. Before the list, here is the sector context that explains why a bank data breach costs what it does and where the risk is now concentrated.
Financial services is one of the most expensive industries to be breached in. The IBM Cost of a Data Breach Report 2025 puts the average financial services breach at USD 5.56 million, second only to healthcare and roughly 25% above the USD 4.44 million global average across all industries. The same report shows the sector's cost easing from USD 6.08 million in the 2024 edition, in line with the first global decline in five years. Any figure labeled as an "IBM 2026" financial-sector number should be treated as unverified until IBM publishes that edition, because several sites relabel 2025 data as 2026.
Cost is only half the picture. The most recent Verizon 2026 Data Breach Investigations Report, built on more than 31,000 security incidents and over 22,000 confirmed breaches across 145 countries, found that vulnerability exploitation has overtaken stolen credentials as the leading breach entry point at 31%, and that ransomware now appears in 48% of breaches. The finding that matters most for the entries below is third-party risk: supply chain involvement rose 60% year over year and now features in 48% of breaches. That single trend explains why so many of the largest financial-sector incidents originated with a vendor rather than the institution named in the headline.
This is one of the largest data exposures ever recorded at a financial institution, and it required no hacking skill at all. First American's own penetration test in December 2018 had identified the flaw, and the company did not remediate it before it became public five months later. The exposed documents were exactly the material needed for mortgage wire fraud and identity theft.
Aftermath: the New York Department of Financial Services filed charges in July 2020, the first enforcement action ever brought under the NYDFS Part 500 Cybersecurity Regulation. First American settled with NYDFS in November 2023 for USD 1 million, and separately settled with the SEC in June 2024 for USD 487,616 over disclosure-control failures. A separate December 2023 cyberattack affected around 44,000 individuals.
Source: KrebsOnSecurity | NYDFS | SEC
Equifax remains the defining consumer data breach and one of the biggest data breaches in history. The victims were not customers, had no relationship with Equifax, and had never consented to it holding their data, which is what made it politically explosive. Nearly half the US adult population had the identity-verification triad of name, Social Security number, and date of birth stolen at once. Four members of the Chinese People's Liberation Army were indicted for the intrusion in February 2020.
Aftermath: a global settlement with the FTC, CFPB, and 50 US states and territories announced in July 2019 required Equifax to pay at least USD 575 million and up to USD 700 million. The company also agreed to a USD 13.5 million payment with eight state banking regulators, and the UK ICO fined Equifax Ltd GBP 500,000, the maximum under the pre-GDPR Data Protection Act 1998. Equifax committed roughly USD 1.25 billion in incremental technology and security spending, and its CEO, CIO, and CSO all departed.
Source: FTC | US GAO report | ICO fine coverage
Heartland was the largest payment card breach in history when disclosed, and it exposed the central weakness of the PCI DSS regime. Heartland had been certified PCI compliant by a qualified security assessor shortly before the breach. The attackers sat inside for months capturing data in flight, in the one place the standard did not require encryption at the time. The incident drove the industry toward end-to-end encryption, tokenization, and eventually EMV chip adoption in the US.
Aftermath: Heartland disclosed roughly USD 145 million in breach-related expenses, including settlements with Visa, MasterCard, American Express, and Discover, plus fines and legal costs. Albert Gonzalez was sentenced to 20 years in federal prison in March 2010, the longest US sentence for computer crime at the time. Heartland's share price fell by around 80% in the months after disclosure, and the company was later acquired by Global Payments in 2016.
Source: KrebsOnSecurity | US Department of Justice
Capital One was the cloud era's first mega-breach at a major bank, and it is the canonical case study for cloud misconfiguration and excessive IAM privilege rather than perimeter failure. The attacker, Paige Thompson, was a former AWS engineer who found the misconfiguration and then posted about the data on GitHub and Slack, which is how Capital One found out. It is the reason instance metadata service v2 and least-privilege IAM review became standard bank audit items.
Aftermath: the Office of the Comptroller of the Currency assessed an USD 80 million civil money penalty in August 2020, and the Federal Reserve issued a cease and desist order. Capital One agreed to a USD 190 million class action settlement in December 2021. Paige Thompson was convicted on seven counts in June 2022 and sentenced in October 2022 to time served plus five years of probation.
Source: OCC | Capital One | US Department of Justice
TJX was the largest card breach in history until Heartland superseded it, and the same crew ran both. Its lasting significance is legal rather than technical. The settlements TJX reached with Visa and MasterCard established the template by which card networks pass fraud and reissuance costs back through acquirers to breached entities. Global Payments five years later showed the reputational mechanism specific to processors: it was removed from Visa's list of PCI DSS compliant service providers, an existential commercial event for a processor.
Aftermath: TJX disclosed breach costs of approximately USD 256 million, plus a multistate attorney general settlement of USD 9.75 million in 2009 and an FTC consent order requiring 20 years of biennial security audits. Global Payments reported cumulative breach costs of approximately USD 121 million and regained its compliant listing status after remediation.
Source: FTC | KrebsOnSecurity
JPMorgan spent roughly USD 250 million a year on cybersecurity at the time and was still breached because a single server in a very large estate had been missed in a two-factor authentication rollout. That is the enduring lesson. In an estate of tens of thousands of servers, coverage gaps rather than attacker sophistication determine outcomes. The scale, roughly two-thirds of US households, made it the largest bank breach disclosed at that point.
Aftermath: no regulatory fine was imposed, largely because no account credentials or financial data were taken. The US Attorney for the Southern District of New York indicted Gery Shalon, Ziv Orenstein, and Joshua Samuel Aaron in November 2015, describing the intrusion as part of a sprawling securities fraud and unlicensed bitcoin exchange enterprise. JPMorgan roughly doubled its annual cybersecurity budget to USD 500 million.
Source: SEC 8-K | US Department of Justice indictment
Santander was one of the highest-profile victims of the 2024 Snowflake campaign, which also hit Ticketmaster, AT&T, Advance Auto Parts, and around 165 other organizations. The vector was not a Snowflake platform vulnerability but customer-side identity failure: valid credentials, no multi-factor authentication, no network restriction. It also ranks among the most significant European data breaches of recent years. For financial services it crystallized the risk of moving large customer datasets into cloud data warehouses without enforcing the identity controls applied to core banking.
Aftermath: Santander notified customers and regulators in the affected markets and said its banking systems and transactions were unaffected. Two suspects linked to the campaign were arrested, including Connor Moucka in Canada in October 2024. Snowflake subsequently made multi-factor authentication enforceable by default. No fine against Santander had been announced as of July 2026.
Source: Reuters | SecurityWeek
LoanDepot took systems offline, including its customer portals and phone lines, leaving borrowers unable to make mortgage payments or complete closings for roughly two weeks in the middle of transactions with contractual deadlines. Because mortgage files contain a complete financial profile, from Social Security number to income to bank accounts, non-bank mortgage companies are among the highest-value targets in the sector while typically operating with thinner security programs than regulated depositories.
Aftermath: LoanDepot recorded approximately USD 26.9 million in cyberattack-related expenses in 2024 and disclosed material impacts on origination volume. Consolidated class action litigation in the Central District of California settled for approximately USD 25 million, approved in 2025.
Source: SEC | SecurityWeek
Mr. Cooper had to take systems offline, which prevented borrowers from making payments during a month-end and quarter-end cycle. The affected population included people who had never chosen Mr. Cooper. Because mortgage servicing rights are bought and sold, the company held records for borrowers whose loans it had acquired, meaning millions of victims had no idea it held their data. Together with LoanDepot two months later, it made US mortgage servicing the most breached corner of financial services in that period.
Aftermath: Mr. Cooper recorded approximately USD 25 million in vendor and remediation costs. More than 20 class actions were consolidated in the Northern District of Texas. No public fine had been announced as of July 2026.
Source: SEC | BleepingComputer
Latitude's disclosure escalated dramatically over ten days, from an initial estimate of 328,000 records to 14 million, which severely damaged trust in its incident communications. Because Latitude retained identity documents from credit applications going back to 2005, people who had taken out an interest-free retail finance deal nearly two decades earlier found their license and passport details stolen. Latitude refused to pay the ransom. It is the largest Australian financial-sector breach on record and features in our wider list of the biggest data breaches in Australia.
Aftermath: Latitude reported incident costs of approximately AUD 76 million in its FY2023 results and posted a statutory loss. The Office of the Australian Information Commissioner opened inquiries into the breach, and a class action followed. Arriving months after Optus and Medibank, the breach was a direct driver of Australian government reform on data retention obligations.
Desjardins is the largest breach of a Canadian financial institution and the largest insider-driven financial breach in North America. No perimeter was breached and no vulnerability was exploited. An authorized user with legitimate access to member data simply took it, repeatedly, for over two years without triggering any control. It reframed insider risk from a theoretical concern to a board-level one across Canadian financial services.
Aftermath: the Office of the Privacy Commissioner of Canada concluded in December 2020 that Desjardins had contravened PIPEDA. Desjardins reported roughly CAD 108 million in pre-tax costs in 2019 alone and offered all members free credit monitoring. A CAD 200.9 million class action settlement was approved by the Quebec Superior Court in 2021 and 2022, and Quebec's Law 25 privacy reform was shaped in part by this breach.
Source: Office of the Privacy Commissioner of Canada | Reuters
The vector is the one that recurs across fintech: offboarding failure. A departed employee retained the ability to pull reports on millions of brokerage customers, and Block only found out months later. The exposed data was portfolio holdings and account numbers, precisely the material for targeted social engineering of investors. Block's four-month delay between the December download and the April disclosure drew criticism.
Aftermath: class actions were consolidated. Separately, and not arising from this breach, in January 2025 Block faced two major regulatory actions over Cash App: a coordinated settlement with 48 state financial regulators requiring an USD 80 million penalty, and a CFPB order requiring approximately USD 175 million. These should be read as regulatory findings against Block's controls generally, not as penalties for the 2021 insider breach.
Evolve is the clearest illustration of the sponsor bank problem. It provided the banking rails behind fintechs including Affirm, Wise, Mercury, Bilt, and, notoriously, Yotta via the failed intermediary Synapse, which meant millions of people whose data was stolen had never heard of Evolve. Notification was consequently chaotic, and the breach landed while the bank was already under supervisory pressure.
Aftermath: the Federal Reserve Board issued an enforcement action against Evolve on June 14, 2024, twelve days before the breach became public, citing deficiencies in anti-money laundering, risk management, and consumer compliance in its fintech partnerships. The timing made Evolve the emblem of regulators' broader concerns about banking as a service. Class actions were consolidated in the Western District of Tennessee.
Source: Federal Reserve | SecurityWeek
Eight years after Equifax, the second of the big three US bureaus disclosed a breach of the same identity triad, this time not through an unpatched server but through a SaaS CRM instance reached by social engineering. That contrast is the point. The sector hardened its own infrastructure, and the attackers moved to the vendor and identity layer. TransUnion was one of more than 700 organizations caught in the 2025 Salesforce-linked campaign, alongside Allianz Life, Farmers Insurance, Google, Workday, and Qantas.
Aftermath: TransUnion offered 24 months of credit monitoring and identity theft protection, and class actions were filed within days. The incident drew congressional attention to whether credit bureaus should face stricter obligations. No fine had been announced as of July 2026.
Source: SecurityWeek | The Record
Prudential is the clearest example in the sector of why initial breach figures should never be treated as final. The company's February 8-K described a limited incident affecting 36,545 people. Four months later the count filed with Maine was seventy times larger. Prudential also filed its 8-K within days of the SEC's new four-business-day cyber disclosure rule taking effect, making it one of the earliest tests of that regime.
Aftermath: Prudential offered 24 months of credit monitoring, and class actions were filed in New Jersey. The revision itself became a case study in SEC disclosure practice, since the materiality assessment behind the original 8-K rested on a figure that proved wildly low. No fine had been announced as of July 2026.
Source: SEC | The Record
Allianz Life was among the first confirmed victims of the 2025 Salesforce vishing campaign, and it notified within ten days, which is unusually quick for the sector. The attackers never touched Allianz Life's infrastructure. The entire loss occurred in a SaaS tenant obtained by phoning a human being. For insurers, which hold beneficiary designations and full identity profiles, this is the highest-consequence version of the vendor-identity problem.
Aftermath: Allianz Life notified the FBI and Minnesota regulators and offered two years of credit monitoring and identity theft restoration. Multiple class actions were filed in the District of Minnesota, and Allianz Life confirmed the breach did not affect Allianz SE's other operating entities. No fine had been announced as of July 2026.
Source: Office of the Maine Attorney General | SecurityWeek
Flagstar is the definitive example of compounding third-party risk in banking: three mass breaches in three years, in 2021 via Accellion FTA, in 2022, and in 2023 via MOVEit through Fiserv, none of which originated in Flagstar's own systems. The broader Cl0p MOVEit campaign is the largest single-vulnerability mass exploitation event on record, affecting more than 2,770 organizations and, by common estimates, over 95 million individuals, with financial services heavily represented.
Aftermath: Flagstar, by then part of New York Community Bancorp, offered credit monitoring and faced class action litigation. Progress Software, MOVEit's vendor, disclosed an SEC investigation and shareholder litigation. The campaign led CISA and the FBI to issue joint advisories on Cl0p and accelerated scrutiny of managed file transfer software across the sector.
Source: Banking Dive | CISA advisory AA23-158A
This is the largest financial-sector supply chain breach to emerge in the first half of 2026, and it follows the now-familiar pattern. A mid-sized vendor serving dozens of small and mid-sized institutions is compromised through an edge security appliance, and the aggregate victim count dwarfs anything those individual banks would have suffered alone. Because each institution notifies separately, the incident is systematically under-counted in breach trackers.
Aftermath: notifications and credit monitoring were offered by the individual financial institutions. Given the number of affected regulated entities, examination-level scrutiny from the OCC, FDIC, and NCUA is likely. Regulatory and litigation outcomes were not known as of July 2026, and details beyond the affected-institution count should be treated as provisional.
This is one of the larger single-institution US bank breaches confirmed in the first half of 2026. At roughly 183,000 individuals it is modest by the standards of the entries above, which is itself informative. The very large 2026 financial-sector numbers came from vendors, not from banks' own networks. Details remain thin and should be checked against the bank's own notice and state attorney general filings before publication.
Aftermath: notifications were issued and credit monitoring offered. No regulatory action or litigation outcome was known as of July 2026.
The vector here is distinctive and under-appreciated: no vulnerability, no phishing, no vendor. The attacker legitimately signed up, then exploited a flaw in how the platform scoped document access for authenticated users. Any financial platform with self-service onboarding and document retrieval carries this risk, and patching or multi-factor authentication will not catch it. Fidelity administers roughly USD 14 trillion in assets, so even a five-figure victim count is significant.
Aftermath: Fidelity offered 24 months of credit monitoring and identity restoration through TransUnion, and class actions were filed in Massachusetts. Fidelity closed the two fraudulent accounts and said it had remediated the access issue. No fine had been announced as of July 2026.
Source: Office of the Maine Attorney General | TechCrunch
Truist's significance is disclosure practice rather than scale. The bank had detected and contained an incident in October 2023, believed it resolved, then found the data for sale publicly eight months later. That gap between containment and discovery of exfiltration is common and rarely acknowledged. The alleged inclusion of IVR funds-transfer source code, if accurate, would matter more than the employee records, since it maps a live payment authorization path. This entry should be read as attributed to the seller's claims rather than confirmed fact.
Aftermath: Truist said it had hardened the affected systems and that the incident did not involve customer accounts. Given the disputed contents, no confirmed victim notification program of scale was made public, and no regulatory action had been announced as of July 2026.
Source: American Banker
Bank of America itself was never breached. Its customers' data was exposed because a vendor's subsidiary was hit, and Bank of America was only one of dozens of downstream clients that also included Fidelity Investments Life Insurance, Union Labor Life, and Oceanview Life and Annuity. This is the archetypal financial services fourth-party incident, and the reason vendor concentration in insurance and retirement plan administration is now a named supervisory concern.
Aftermath: Infosys McCamish agreed to a class action settlement of approximately USD 17.5 million, approved in 2025, covering the full 6.5 million affected population. Bank of America offered affected participants 24 months of identity theft protection, and multiple state attorneys general reviewed the notification timeline, which ran several months behind the incident.
Source: Office of the Maine Attorney General | BleepingComputer
This is a confirmed first-half 2026 breach at a major US wealth manager, disclosed through state attorney general channels rather than a headline announcement, which is how most mid-scale financial breaches now surface. The count is modest, but the population matters. High-net-worth wealth management clients are prime targets for subsequent social engineering and account takeover, so the downstream fraud value per record is far above average.
Aftermath: notifications were issued and credit monitoring offered. No regulatory action or litigation outcome was known as of July 2026, and the figures should be verified against the Oregon DOJ and other state filings before publication.
Source: Tech.co | Oregon Department of Justice
The affected count is small, but the case matters because it is the third generation of the same attack pattern in the sector. Clop exploited Accellion FTA in 2021, MOVEit Transfer in 2023, and Cleo in late 2024, each time hitting financial institutions through vendors that used managed file transfer software to move bulk customer files. Western Alliance also disclosed the incident in an SEC filing under the cyber disclosure rule, giving a clean public record of a Cleo-campaign victim in banking.
Aftermath: Western Alliance offered credit monitoring and identity protection and stated the incident did not have a material impact on operations. Cleo issued patches, CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog, and class action litigation was filed.
Source: SecurityWeek | CISA Known Exploited Vulnerabilities catalog
Finastra serves more than 8,000 financial institutions, including 45 of the world's top 50 banks, which makes it one of the highest-consequence single points of failure in global finance. For more incidents affecting UK-headquartered organizations, see the biggest data breaches in the UK. The breach's importance is not the record count, which was never established, but the demonstration that a core banking software vendor's file exchange infrastructure can be entered with stolen credentials. A threat actor using the handle abyss0 offered the data for sale before withdrawing the listing.
Aftermath: Finastra notified affected clients directly and engaged a third-party forensics firm, and said the incident was contained to the file transfer platform. Because its counterparties are institutions rather than consumers, no mass consumer notification followed. This entry is included for systemic significance rather than scale.
Source: KrebsOnSecurity | Infosecurity Magazine
American Express's notice was explicit that its own systems were not compromised and that the exposure arose at a merchant processor, which is why it could not name a single accountable entity to consumers. The absence of any published victim count is itself notable. Card issuers routinely reissue cards after processor breaches without ever quantifying exposure publicly, which means processor breaches are systematically invisible in breach statistics. This entry is presented with the count explicitly marked as undisclosed.
Aftermath: American Express advised affected card members to review statements and enable transaction alerts, and issued replacement cards where warranted. Because card network rules place fraud liability on issuers and acquirers rather than consumers, direct consumer harm was limited to reissuance friction. No regulatory action against American Express followed.
Source: BleepingComputer | Massachusetts Attorney General
Three first-half 2026 incidents appear above as ranked entries: Marquis Software Solutions (up to approximately 1.35 million customers across 74 or more US financial institutions, via a SonicWall vulnerability), Heritage Bank (182,793 individuals, March to April 2026), and Ameriprise Financial (up to 47,876 individuals, March 2026). The pattern in the first half of 2026 mirrors 2024 and 2025 rather than departing from it:
One caveat carries real weight here. First-half 2026 financial-sector figures are provisional, and counts in vendor-originated incidents are routinely revised upward months later, as Conduent, Prudential, and Infosys McCamish all demonstrate.
The throughline across these 26 incidents is that the largest recent breaches are vendor-originated and identity-driven, and the vendor is usually invisible to the affected customer. Managing that risk, and learning how to prevent third-party data breaches, means watching your own attack surface, your vendors, and your workforce at the same time. That is where UpGuard focuses:
Continuous monitoring across all three surfaces is what turns a reactive notification process into an early warning system, and it underpins any serious effort to reduce the risk of data breaches. To see how it works on your own environment, start a free trial.
Recent confirmed financial-services incidents include TransUnion and Allianz Life, both breached through the 2025 Salesforce social-engineering campaign, and the 2026 Marquis Software Solutions and Heritage Bank incidents. Many of these reached the institution through a third-party system rather than its core banking network.
First American Financial Corporation's exposure of approximately 885 million documents is the largest financial-sector data exposure on record, though that is a count of documents dating back to 2003, not a count of individuals.
Increasingly, no. The Verizon 2026 Data Breach Investigations Report found that third-party involvement now features in 48% of breaches, and several of the largest financial-sector incidents originated at a vendor rather than the named institution.
Watch for breach-notification letters and check your state attorney general's data breach filings, monitor your account statements for unfamiliar activity, and enroll in any official credit-monitoring offer provided after an incident.