Skip to content
Back to Blog
critical severity June 15, 2026 · 4 min read

Bank of America Data Breach Notice (Massachusetts Attorney General)

If you received a notice from Bank of America, here’s what the filing says was exposed, and what to do about it.

Bank of America notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on June 15, 2026, and the notice lists social security numbers and financial account numbers among the information exposed.

Bank of America Data Breach Notice (Massachusetts Attorney General)

The filing from Bank of America, submitted to the Massachusetts Attorney General on June 15, 2026, states that one person’s records were exposed. Those records included both a Social Security number and financial account numbers.

A Social Security number cannot be replaced

If you were the individual named in this filing, the most serious element is the Social Security number. Unlike a credit card or password, a Social Security number is permanent. It cannot be reissued on request the way a compromised account credential can. Once it has left the organisation’s control it remains usable for identity theft and fraud for the rest of your life.

The financial account numbers listed in the filing add a second, more immediate risk. These can be used to initiate unauthorized transfers, open new accounts in your name, or file fraudulent tax returns. Because the record lists both categories together, anyone affected faces the combination of a permanent identifier and live financial details.

What the single-person filing actually tells you

The Massachusetts filing reports exactly one individual. That is not a placeholder or an estimate; it is the number the organisation provided under state law. For you, this means the breach is either extremely narrow or the notice is limited to your specific record. In either case, the exposure is real and the categories involved are among the most sensitive that appear in breach notifications.

No passwords were exposed. The filing does not list any credential fields, so there is no need to change a Bank of America password because of this incident. That is one piece of good news in an otherwise serious notice.

How this exposure can be used against you

With your Social Security number and financial account information, a fraudster can:

  • File a tax return in your name and claim refunds before you do
  • Apply for new credit cards or loans using your SSN as the primary identifier
  • Impersonate you when contacting banks or government agencies that already hold your account details
  • Combine the data with publicly available information to build a convincing identity profile

These risks do not expire when the news cycle moves on. The data retains its value indefinitely.

The letter is the only reliable way to know if this concerns you

Bank of America is required to notify affected Massachusetts residents directly, usually by mail. If you have not received a letter, it is likely that your information was not included in this filing. However, if you have moved since the incident occurred, the letter may have gone to an old address. In that case you should contact Bank of America directly to confirm whether your records were part of the notice.

The filing itself does not state when the incident occurred, only the date it was reported to the state. There is therefore no way to calculate how long the data may have been accessible before notification.

Why this matters more than most single-person filings

Most people assume a breach affecting one person must be minor. In this case the opposite is true. When an organisation of Bank of America’s size reports a breach this narrowly scoped yet still includes both Social Security numbers and financial account numbers, it usually means the exposed record was complete and highly usable. The quality of the data outweighs the quantity.

Because Social Security numbers cannot be changed, the protective steps you take now must be permanent rather than temporary. Credit monitoring alone is not enough. You need controls that last for years.

Concrete measures that address exactly these exposures

Place a freeze on your credit files at Equifax, Experian, and TransUnion. This prevents new credit accounts from being opened in your name even if someone has your Social Security number. The freeze is free and can be lifted temporarily when you need to apply for credit.

Review every account you hold at Bank of America and enable the strongest available authentication. Although no passwords were exposed here, the financial account numbers themselves can still be used if an attacker can reach those accounts through other means.

File your taxes as early as possible each year. This reduces the window during which someone could file a fraudulent return using your SSN. If you receive a notice from the IRS that a return has already been filed under your number, act immediately.

Monitor your bank and credit card statements daily for the next several months. Look for small test charges or unfamiliar transactions that often precede larger fraud. Set up account alerts for any transaction above $1.

Consider placing an extended fraud alert on your credit files. This requires creditors to verify your identity before issuing new credit and lasts for one year, renewable if needed.

The filing does not indicate whether a third-party vendor was involved or how the data was accessed. Those details remain unknown. What is known is that one person’s Social Security number and financial account numbers are now outside Bank of America’s control. The steps above are the only practical ways to limit what can still be done with that information.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Bank of America.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed June 15, 2026
Last reviewed July 22, 2026
Affected 1
Data exposed Social Security numbersFinancial account numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email