Bank of America warned customers after document destruction vendor mishandled records

Organization
Bank of America
Exploit
Third-Party Data Breach
Industry
Financial Services

Bank of America notified a group of customers in early 2025 that their personal information may have been exposed after a third-party document destruction vendor failed to secure bank records while moving them. According to the notification letters, documents were found outside their secure containers on the exterior of a financial center on December 30, 2024.

The bank said the paperwork could have contained names, account and other financial information, home and business addresses, phone numbers, email addresses, dates of birth, sex, Social Security numbers and other government identification numbers. Because the vendor could not establish whose documents were involved, the bank wrote to everyone whose records might have been in the shipment.

Bank of America did not publish a total. Security.org reported that at least two Massachusetts customers were confirmed affected and noted that the full scope was hard to establish given that the exposure involved physical paper rather than a computer system. The bank told customers it was monitoring potentially affected accounts.

Affected customers were offered two years of complimentary identity theft protection through an Experian service that included credit and dark web monitoring. Benzinga reported that the disclosure followed a similar notification in January 2025 covering roughly 414 customers, and that recent exposures of Bank of America customer data have originated with outside vendors rather than the bank's own systems.

Sources