← TD Bank

2026 TD Bank U.S. — insider unauthorized access; SSNs, account numbers, transactional data (Jan)

2026 Unknown records affected Share on X

Data compromised

Per TD notification letter filed with Massachusetts: names, addresses, phone numbers, dates of birth, Social Security numbers, account numbers, and transactional data; victim count not disclosed in public filing excerpts

Technical writeup

Verified insider data breach — disclosed mid-June 2026. TD Bank U.S. reported to Massachusetts regulators and affected customers that an employee accessed customer information without authorization from January 7 through January 30, 2026. Notification letters filed on the Massachusetts Office of Consumer Affairs and Business Regulation June 2026 breach archive state exposed categories may include name, address, phone number, date of birth, Social Security number, account number, and transactional data. TD classified the event as an insider incident and said at disclosure it had no evidence of external hacking or further misuse. The bank offered a complimentary two-year Fraud Defender membership through Merchants Information Solutions and said it would cover expenses for customers who choose to close and reopen accounts. Public reporting did not include a statewide or nationwide victim count at catalog time. BreachHistory indexes recordsAffected 0 pending attested totals.

Root cause

TD Bank U.S. employee accessed customer records without authorization January 7–30, 2026; insider incident per Massachusetts regulator filing and customer notification

References