M&T Bank Data Breach Notice (Massachusetts Attorney General)
If you received a notice from M&T Bank, here’s what the filing says was exposed, and what to do about it.
M&T Bank notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on July 17, 2026, and the notice lists financial account numbers among the information exposed.
The single piece of information exposed in this incident is your financial account number. Because that number remains tied to your M&T Bank accounts, it can still be used by someone who obtains it to attempt fraud such as unauthorized transfers, new account creation in your name, or impersonation when dealing with other financial institutions.
One person in Massachusetts is named in this filing
M&T Bank submitted this notice to the Massachusetts Attorney General on July 17, 2026. The record lists financial account numbers as the exposed category and states that one individual was affected. No other categories of information appear in the filing.
What a financial account number actually enables
Unlike a credit card number that can be replaced, a bank account number combined with routing information functions as a long-term identifier. Someone who has it can attempt to initiate ACH transfers, set up bill payments, or use it as supporting evidence when applying for credit or government benefits in your name. The exposure does not automatically mean fraud has occurred, but it does mean the number must be treated as permanently compromised.
No passwords, Social Security numbers, dates of birth, or government identifiers were listed in the filing. This is genuinely good news. The absence of those fields removes many of the classic identity-theft pathways that make other breaches far more dangerous.
Your bank account itself is not compromised
The filing does not indicate that login credentials were taken or that attackers gained direct access to M&T online banking. Your ability to log in, change passwords, or control the account remains intact. The risk is limited to what someone can do with the account number on its own or when paired with information obtained elsewhere.
How to determine whether this filing includes you
M&T Bank is required to notify affected customers directly, usually by mail. If you have not received a letter from the bank, it is likely you were not part of this incident. However, because the filing does not state when the incident occurred, anyone who has moved addresses in recent years should contact M&T Bank directly to confirm whether their records were included.
The permanent nature of this exposure
Financial account numbers cannot be reissued in the same way a compromised credit card can. Once the number is out, it stays out. That permanence changes how you monitor the account going forward. Routine checks that might have been monthly may now need to become weekly, at least for the next year.
What this means for fraud monitoring
With only an account number exposed, the most common attacks involve attempts to drain funds through wire transfers, add unauthorized payees, or open new lines of credit using the account as proof of identity. Banks can usually reverse fraudulent ACH transfers if caught quickly, but the window for that reversal is limited. Early detection matters.
M&T Bank has likely already placed alerts on the affected account. You should still verify that yourself and consider adding additional layers such as requiring verbal confirmation for any transfer above a certain amount.
Practical controls you can put in place today
Place a fraud alert with the three major credit bureaus even though no Social Security number was exposed. This forces creditors to verify your identity before opening new accounts and adds a useful paper trail. Freeze your credit reports if you do not anticipate needing new credit soon. The freeze does not affect your existing M&T accounts.
Review every linked external account that pulls from or pushes to your M&T checking or savings. Update any outdated login information and enable transaction alerts that notify you immediately of any movement, no matter how small. Many banks now offer real-time push notifications for every debit.
Request that M&T Bank issue you new account numbers if they have not already done so. Some institutions will do this automatically for breach-related incidents; others require a customer request. New numbers close the most direct path an attacker could use.
Continue monitoring your accounts closely for at least twelve months. Look specifically for small test transactions that fraudsters sometimes use before attempting larger ones. Set up paperless statements and make sure your email account is secured with its own strong, unique password and multi-factor authentication.
The filing contains no information about how the incident occurred. It does not state whether the exposure resulted from a cyber attack, an insider event, lost media, or a vendor issue. Those details remain unknown to the public. What matters for you is the narrow scope of what was actually listed: one category, one person, and no biographic identifiers that would make widespread identity theft straightforward.
This is a contained but real risk. Treat the account number as public from now on. Adjust your monitoring habits accordingly, confirm your status with the bank if you have any doubt, and move on with the practical controls that still rest in your hands.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on M&T Bank.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
French FICOBA National Bank Account Registry Hack — February 2026
France's FICOBA national bank-account registry was breached in late February 2026, exposing tens of …
The Cecilian Bank Listed by Storm Ransomware Group
The Cecilian Bank is an FDIC-insured financial institution that offers a wide range of personal and …
PT. Bank Perekonomian Rakyat Bintan NEW Listed by Coinbase Cartel Ransomware Group
Banking & Financial Services - $5 Million…