2024 Citibank N.A. (Citi Cards) — online/account access incident; June regulatory notices
Data compromised
Cardholder identity, card account identifiers, and recent transaction detail per sample regulatory notification text
Technical writeup
Citibank consumer card operations filed state breach samples in early June 2024 describing unauthorized access to online account features that exposed names, masked or full card numbers, and transaction metadata for a population security blogs summarized at roughly three hundred fifty thousand Rewards+ card relationships. Massachusetts mirrors and API-security post-mortems paired the notices with parameter-tampering narratives in industry analysis.
Root cause
Unauthorized manipulation of web or API account-access paths (per public security analyses summarized alongside bank letters)