KeyBank

KeyBank

On May 12, 2023, KeyBank experienced a data breach caused by insider wrongdoing, as reported by the Maine Attorney General's Office on June 7, 2023. The incident compromised sensitive information, including financial account numbers and personal details of **181 individuals**, among whom **3 were residents of Maine**. The exposed data poses a significant risk of identity theft and financial fraud. In response, KeyBank is providing affected individuals with **two years of identity theft protection** through **Equifax Complete Premier** to mitigate potential harm. The breach highlights vulnerabilities in internal controls, as the compromise stemmed from malicious or negligent actions by an employee or trusted insider. While the scale of the breach is relatively contained in terms of affected individuals, the nature of the exposed data—financial and personal—heightens the severity due to the potential for long-term fraudulent exploitation.

Source: https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/9c057611-011c-45d9-9308-be0c7e0d9763.shtml

TPRM report: https://www.rankiteo.com/company/keybank

"id": "key717082025",
"linkid": "keybank",
"type": "Breach",
"date": "5/2023",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 181,
                        'industry': 'Banking/Financial Services',
                        'location': 'United States',
                        'name': 'KeyBank',
                        'type': 'Financial Institution'}],
 'attack_vector': 'Insider Threat',
 'customer_advisories': 'Two years of identity theft protection offered to '
                        'affected individuals via Equifax Complete Premier',
 'data_breach': {'number_of_records_exposed': 181,
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Financial account numbers',
                                              'Personal details']},
 'date_detected': '2023-05-12',
 'date_publicly_disclosed': '2023-06-07',
 'description': "The Maine Attorney General's Office reported a data breach "
                'involving KeyBank on June 7, 2023. The breach occurred on May '
                '12, 2023, due to insider wrongdoing, affecting 181 '
                'individuals, including 3 residents of Maine. The compromised '
                'information included financial account numbers and personal '
                'details, and KeyBank is offering two years of identity theft '
                'protection through Equifax Complete Premier.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'insider breach and exposure of '
                                       'sensitive data',
            'data_compromised': ['Financial account numbers',
                                 'Personal details'],
            'identity_theft_risk': 'High (financial account numbers and '
                                   'personal details exposed)',
            'payment_information_risk': 'High (financial account numbers '
                                        'compromised)'},
 'initial_access_broker': {'high_value_targets': ['Financial account numbers',
                                                  'Personal details']},
 'post_incident_analysis': {'root_causes': 'Insider wrongdoing (intentional or '
                                           'negligent misconduct by an '
                                           'employee/associate)'},
 'references': [{'date_accessed': '2023-06-07',
                 'source': "Maine Attorney General's Office"}],
 'regulatory_compliance': {'regulatory_notifications': 'Maine Attorney '
                                                       "General's Office (and "
                                                       'potentially other '
                                                       'state regulators, '
                                                       'given the multi-state '
                                                       'impact)'},
 'response': {'communication_strategy': 'Public disclosure via Maine Attorney '
                                        "General's Office; likely direct "
                                        'notification to affected individuals',
              'remediation_measures': 'Offering two years of identity theft '
                                      'protection (Equifax Complete Premier) '
                                      'to affected individuals',
              'third_party_assistance': 'Equifax (for identity theft '
                                        'protection services)'},
 'threat_actor': 'Insider (Employee/Associate)',
 'title': 'KeyBank Data Breach Due to Insider Wrongdoing',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.