Sev0AI security incidents, tracked

All incidents / Supply chain and access

US bank reported customer SSNs entered into an unauthorized AI app

Community Bank, disclosed 12 May 2026. Supply chain and access Data exposed High

Community Bank disclosed in an SEC filing that customer names, dates of birth and Social Security numbers had been entered into an unapproved AI application. The bank opened an investigation and notified regulators.

Disclosed
12 May 2026
Organization
Community Bank
Vendor
Unknown
Kind of AI
AI app
AI's role
AI was the way in
How it happened
Supply chain and access: Shadow AI
Harm
Data exposed
Data involved
Personal data, Financial
Reach
One organization
Severity
High
Model at fault
No
Status
Confirmed
Country
US

Sources

  1. https://www.theregister.com/security/2026/05/12/us-bank-reports-itself-after-ai-customer-data-mishap/5238787

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "US bank reported customer SSNs entered into an unauthorized AI app", https://sev0.fyi/incidents/2026-05-12-community-bank-unauthorized-ai-app/