Wells Fargo employee sent customer data to a personal account
- Organization
- Wells Fargo
- Exploit
- Malicious Insider
- Industry
- Banking
Wells Fargo notified customers in April 2024 that their information had been exposed by one of its own staff rather than by an external attack. The bank said an employee had breached company policy by sending customer information to a personal account.
According to the notification letters, the exposed data included client names and mortgage account numbers. Wells Fargo said the employee was no longer with the bank. Cybernews, which first reported the incident, said two notification letters had been sent, and Wells Fargo did not publish a total number of people affected.
The bank told recipients it took its responsibility to safeguard information seriously, that it had responded promptly and that it was monitoring the affected accounts for suspicious activity or changes. It offered a complimentary two-year subscription to Experian IdentityWorks, covering credit report monitoring at the three national bureaus, internet surveillance and identity restoration support, with 60 days to enrol, and set up a dedicated customer advocacy team to handle questions.
Wells Fargo did not say when the data was sent or how long it went undetected. The incident was distinct from a later disclosure in September 2024, in which the bank told regulators that a former employee had accessed customer records between May 2022 and March 2023 and used some of them fraudulently.