People search Citigroup data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 13 Citigroup-linked incidents, with headline counts up to 3.9M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Citigroup breach history matters
Citigroup operates in Finance (United States). Across indexed rows, recurring themes include cloud and database misconfiguration, third-party and supply-chain exposure, zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2013 — — Citigroup: Citigroup exposed the Social Security numbers,…
Cataloged incident. Citigroup exposed the Social Security numbers, dates of birth, and other sensitive information of customers by not properly redacting the information for court records. Consumers who went into bankruptcy between 2007 and 2011 were affected. The incident was discovered by the bank on April 2011. Roughly 146,000 consumers were notified of the breach in July of 2013. Exposed categories include Personal information. BreachHistory cites approximately 146K+ affected records in this row. See the citigroup2013 and canonical BreachHistory entry.
2013 — — Citigroup: Third big data breach from Citigroup, 150K records
Cataloged incident. Third big data breach from Citigroup.The personal information of 150,000 consumers who went into bankruptcy between 2007 and 2011 – including their social security numbers – were exposed after Citi failed to properly redact court records before they were put on the Public Access to Court Electronic Records (PACER) system. BreachHistory cites approximately 150K+ affected records in this row. See the citigroupu2 and canonical BreachHistory entry.
2011 — — Citigroup: A breach of an unnamed merchant or merchants may…
Cataloged incident. A breach of an unnamed merchant or merchants may have resulted in the exposure of customer credit and debit card information. Citigroup deactivated the credit cards of affected customers and notified them that Citigroup had been informed of a security breach at a retailer. Within a week, Bank of America also sent new debit cards to some customers after learning that some accounts may have been compromised at a merchant. Exposed categories include Personal information. No attested victim count is published for this row yet. See the citigroup2011 and canonical BreachHistory entry.
2011 — 360k cardholders
Cataloged incident. Hackers exploited a vulnerability in customer website; inserted account numbers into URL to systematically capture data. Names, account numbers, email addresses, and transaction histories exposed. Exposed categories include Email addresses, Names, Addresses, Account numbers, Transaction history. BreachHistory cites approximately 360K+ affected records in this row. See the citi2011 and canonical BreachHistory entry.
2011 — — Citigroup: Data breach reported, 400K records
Cataloged incident. Data breach reported. Reference: http://www.pcworld.com/article/229891/Citigroup_Hack_Nets_Over_200k_in_Stolen_Customer_Details.html BreachHistory cites approximately 400K+ affected records in this row. See the citigroup20111 and canonical BreachHistory entry.
2011 — — Citigroup: Hacking, 360,083 records
Cataloged incident. Data breach reported. financial organization. Method: hacked. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 360K+ affected records in this row. See the citigroup2011-360083-wiki2 and canonical BreachHistory entry.
2010 — — Citigroup: About 600,000 Citigroup customers got a shock…
Cataloged incident. About 600,000 Citigroup customers got a shock earlier this month when they received their annual tax documents with their Social Security numbers printed on the outside of the envelope. The digits were not identified as a Social Security number, and they were printed at the lower edge of the mailing envelope with other numbers and letters that together resembled a mail routing number. Exposed categories include Personal information. BreachHistory cites approximately 600K+ affected records in this row. See the citigroup2010 and canonical BreachHistory entry.
2010 — — Citigroup: Less than 1% of Citbank card holders' names,…
Cataloged incident. Less than 1% of Citbank card holders' names, account numbers, and contact information such as e-mail addresses were stolen. Card security codes were not stolen. BreachHistory cites approximately 360K+ affected records in this row. See the citigroupu1 and canonical BreachHistory entry.
2009 — — Citigroup: Citigroup (NYSE:C) recently issued replacement…
Cataloged incident. Citigroup (NYSE:C) recently issued replacement cards to consumers and told them that their account numbers may have been compromised. Citigroup told credit-card customers in Massachusetts that their account numbers may have been illegally obtained as a result of a merchant database compromise and could be at risk for unauthorized use. Bank officials are not certain if this is a new breach or a previously disclosed one. Exposed categories include Personal information. No attested victim count is published for this row yet. See the citigroup2009 and canonical BreachHistory entry.
2007 — — Citigroup: A laptop was stolen from a third party vendor…
Cataloged incident. A laptop was stolen from a third party vendor during an office burglary. The information on the laptop may have included customer names, Social Security numbers, addresses, telephone numbers and email addresses. The information was related to student loans, but did not include financial account information. Exposed categories include Personal information. BreachHistory cites approximately 519 affected records in this row. See the citigroup2007 and canonical BreachHistory entry.
2006 — — Citigroup: An employee from a Pennsylvania branch reported a…
Cataloged incident. An employee from a Pennsylvania branch reported a missing laptop after a flight. It is believed that the laptop may have been stolen from the employee's luggage after the bags were checked-in for a flight from Chicago to Philadelphia sometime around August 26. At least 11 New York residents and an unknown number of clients nationwide may have had their names, Social Security numbers, addresses and other information exposed. Exposed categories include Personal information. BreachHistory cites approximately 11 affected records in this row. See the citigroup2006 and canonical BreachHistory entry.
2005 — — Citigroup: Customers are being notified that backup tapes…
Cataloged incident. Customers are being notified that backup tapes containing their account information were lost or stolen while being shipped by UPS. Exposed categories include Personal information. BreachHistory cites approximately 3.9M+ affected records in this row. See the citigroup2005 and canonical BreachHistory entry.
2005 — — Citigroup: Blame the messenger, 3.9M records
Cataloged incident. Blame the messenger! A box of computer tapes containing information on 3.9 million customers was lost by United Parcel Service (UPS) while in transit to a credit reporting agency. BreachHistory cites approximately 3.9M+ affected records in this row. See the citigroupu and canonical BreachHistory entry.
Patterns and analysis
- Cloud and database misconfiguration — appears across multiple Citigroup catalog entries; prioritize controls that address this class of failure.
- Third-party and supply-chain exposure — appears across multiple Citigroup catalog entries; prioritize controls that address this class of failure.
- Zero-day exploitation and malware — appears across multiple Citigroup catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the Citigroup company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/citigroup · Latest: citigroup2013.
Sources: BreachHistory catalog (13 rows for Citigroup), company and regulator disclosures cited in individual breach records.