← Blog

HSBC Holdings Data Breaches: Full Timeline Through 2026

Share on X

People search HSBC Holdings data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 6 HSBC Holdings-linked incidents, with headline counts up to 180K+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why HSBC Holdings breach history matters

HSBC Holdings operates in Finance (United Kingdom). Across indexed rows, recurring themes include credential theft and social engineering, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2018 — ~14k U.S. customers

Cataloged incident. Unauthorized access Oct 4–14. Names, addresses, phones, emails, DOB, account numbers, balances, transaction history, payee info. Credential stuffing suspected. Exposed categories include Email addresses, Passwords, Names, Addresses, Phone numbers, Dates of birth, Account numbers, Transaction history. BreachHistory cites approximately 14K+ affected records in this row. See the hsbc2018 and canonical BreachHistory entry.

2016 — — HSBC Holdings: We recently became aware of an incident in which…

Cataloged incident. We recently became aware of an incident in which HSBC's mortgage servicing provider sent encrypted and password pretected disks, which inadvertently included some of your personal information, to an unauthorized commercial third party (a firm that performs financial analytics).  The information was sent between December 7, 2015 and December 8, 2015.  Upon review of some of the data, the third party realized the disks included more information than requested and returned all the disks to the mort Exposed categories include Personal information. No attested victim count is published for this row yet. See the hsbc2016 and canonical BreachHistory entry.

2015 — — HSBC Holdings: HSBC notified customers of a data breach when…

Cataloged incident. HSBC notified customers of a data breach when customer mortgage information was inadvertently exposed via the Internet, which included personal information. The personal information included names, Social Security numbers, account numbers and old account information.The company is providing Identity Guard for 12 months free for those affected.  They can be reached at the Identity Guard Victim Recovery Services phone line at 1-800-901-7107 Monday-Friday 8 a.m-11 p.m, and Saturday 9 a.m-6 p.m East Exposed categories include Personal information. No attested victim count is published for this row yet. See the hsbc2015 and canonical BreachHistory entry.

2012 — — HSBC Holdings: An employee resigned and left with customer account…

Cataloged incident. An employee resigned and left with customer account information.  Names, Account numbers, account types, and phone numbers may have been exposed.  The breach occurred in late July. Exposed categories include Personal information. No attested victim count is published for this row yet. See the hsbc2012 and canonical BreachHistory entry.

2010 — — HSBC Holdings: A caller claiming to be an employee managed to get…

Unverified claim — treat actor counts cautiously. A caller claiming to be an employee managed to get an employee to change the information on 14 customer accounts. Exposed categories include Personal information. BreachHistory cites approximately 14 affected records in this row. See the hsbc2010 and canonical BreachHistory entry.

2005 — — HSBC Holdings: Credit card data was stolen, 180K records

Cataloged incident. Credit card data was stolen. Individuals holding the HSBC-issued General Motors Mastercard were told their cards should be replaced. UPDATE(07/10/07): U.S. Secret Service agents found Ralph Polo Lauren customers' credit card numbers in the hands of Eastern European cyber thieves who created high-quality counterfeit credit cards. Victims are from the U.S., Europe, Asia and Canada, among other places, Several Cuban nationals Exposed categories include Personal information. BreachHistory cites approximately 180K+ affected records in this row. See the hsbc2005 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple HSBC Holdings catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple HSBC Holdings catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the HSBC Holdings company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/hsbc · Latest: hsbc2018.

Sources: BreachHistory catalog (6 rows for HSBC Holdings), company and regulator disclosures cited in individual breach records.