← Community Bank

2026 Community Bank — unauthorized AI app exposed customer PII (SEC notice May 7)

2026 Unknown records affected Share on X

Data compromised

Names, dates of birth, Social Security numbers per SEC summary

Technical writeup

Community Bank, which operates in Pennsylvania, Ohio, and West Virginia, disclosed in a May 7, 2026 U.S. SEC filing that it detected exposure of customer personal data through use of an unauthorized artificial-intelligence-based software application—likely an employee uploading non-public information into an external AI chat service. The bank said affected data included names, dates of birth, and Social Security numbers, described the matter as material due to sensitivity and volume, and stated it was evaluating scope while preparing legally required customer notifications. No consolidated victim count was published in the initial filing summarized by TechCrunch and The Register.

Root cause

Unauthorized use of external AI application leading to customer data exposure

References