MainStreet Bank customer card data exposed in third-party vendor breach
- Organization
- MainStreet Bank (MainStreet Bancshares, Inc.)
- Exploit
- Third-Party Data Breach
- Industry
- Financial Services
MainStreet Bancshares, the Fairfax, Virginia parent of MainStreet Bank, disclosed a security incident at an outside vendor in a filing with the U.S. Securities and Exchange Commission. The bank said it was informed of the vendor compromise in March 2025 and concluded its review on 28 April 2025.
The affected vendor system held payment card information. According to SecurityWeek, the exposed details included cardholder names, card numbers and expiration dates, covering a card processing environment the intruder had access to between April 2023 and April 2025. The bank said Social Security numbers and account numbers were not involved.
Figures for the number of people affected varied slightly across reporting. The company put the total at roughly 4.65% of its customer base, which The Record and several other outlets rounded to about 5%. MainStreet said its own systems were not compromised, that no unauthorized transactions or account takeovers were identified, and that customer services continued to operate normally.
MainStreet said it activated its incident response process on learning of the breach and ended all activity with the provider, noting that each vendor goes through what it called a thorough security vetting process. It reported the incident to regulators, mailed notification letters to affected customers by 26 May 2025, and advised them to obtain replacement cards and review account statements. The bank told investors the incident had no material impact on its operations.