71330 Social Security Numbers Exposed in Bank of America Breach
HEROIC analysts identified a dataset containing Bank of America customer records on a dark web forum, dated November 1, 2023. The breach covered 71,330 records and included some of the most sensitive personal data that can be exposed: Social Security Numbers, full names, birthdates, email addresses, phone numbers, physical addresses, and IP addresses. For a financial institution, this type of breach represents an especially serious event because the data can be used not just for phishing but for direct identity fraud, credit fraud, and account impersonation with the bank itself.
Why Social Security Numbers Make This Bank of America Breach Particularly Severe
Most data breaches expose contact information. This one went further. A Social Security Number combined with a full name, birthdate, address, and phone number is essentially everything a criminal needs to open new credit accounts, file fraudulent tax returns, or apply for loans in your name. Unlike a stolen password, a Social Security Number cannot be changed. Once it is in criminal hands, the risk does not go away. Victims of SSN-based identity theft often spend years dealing with fraudulent accounts and damaged credit, sometmes without realising the source was a breach that hapened years earlier.
What Was Exposed in the Bank of America Breach
- Email Address
- Phone Number
- IP Address
- First Name
- Last Name
- Social Security Number
- Birthday
- Physical Address
- Geographic Location
How Financial Data Breaches Lead to Identity Theft and Fraud
When SSNs, names, and birthdates are all leaked together, the risk is not theoretical. Criminals use this combination to submit fraudulent applications to banks, lenders, and government agencies where identity verification relies on these same data points. They can also use the exposed email and phone number to intercept two-factor authentication codes, bypassing account security on existing accounts. In some cases, attackers use the IP address data to map approximate physical locations and time zone information, which helps them impersonate you more convincingly during social engineering calls. This kind of full-profile exposure is what separates a low-risk breach from one that requires immediate action.
How Financial Institution Database Breaches Work
Banks and financial institutions hold customer data in large, interconnected databases that support everything from account management to loan processing. A database breach at this scale typically occured through one of several routes: a compromised internal credential, a vulnerability in a third-party vendor system, or a direct attack on an application layer that exposes the underlying data store. In the Bank of America case, the dataset appeared on a dark web forum in structured form, consistent with an exfiltration from a customer records database. The data was then listed for sale, which means it was likely recieved by multiple buyers before it was discovered and documented.
Check If Your Bank of America Data Was Exposed
If you are a Bank of America customer, your Social Security Number, contact details, and personal identifiers may already be in circulation. HEROIC's free breach scanner searches across more than 400 billion records to tell you which breaches your email address appears in. This is one of the fastest ways to understand your current exposure. Scan your email for free at HEROIC and take the first step toward protecting your identity.
Breach Breakdown
71,330 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds