Bank of America notifies loan customers after third-party provider breach

Organization
Bank of America
Exploit
Third-Party Data Breach
Industry
Banking & Finance

Bank of America filed a notice of data breach with the Massachusetts attorney general on January 3, 2025 covering customers whose loan information was held by an outside service provider.

The notification said the provider identified unauthorised activity within its software systems on October 1, 2024. The bank stated that its own systems were not involved and that the exposure was limited to data the vendor processed on its behalf. Bank of America did not name the provider.

The data elements listed in the letter were names, addresses, phone numbers, Social Security numbers, passport numbers and loan numbers, a combination that covers both identity documents and account identifiers. Security.org reported that at least 414 customers were notified, a small population relative to the bank's earlier third-party incidents.

Affected customers received mailed letters and were offered a complimentary one-year membership in Experian IdentityWorks identity theft protection. As of the January 2025 reporting no threat actor had publicly claimed the incident, the bank had released no further detail, and plaintiffs' firms had begun advertising investigations into a possible class action.

Sources