Back Americanbanker The seven largest banking data breaches of 2025
Third-party vendor vulnerabilities and sophisticated social engineering campaigns defined the cybersecurity landscape for financial institutions in 2025.
From specialized software providers to major credit bureaus, attackers frequently bypassed internal bank defenses by targeting the supply chain.
Although any data breach can affect banks, which must defend against fraudsters exploiting stolen identity data, this article lists the largest data breaches that directly affected the banking and financial services industry in 2025.
Within the financial services industry, the largest breach of the year affected peer-to-peer lender Prosper Marketplace.
In September, shortly after Prosper discovered the breach, class action attorneys began courting potentially affected customers to be litigants. At the time, media outlets reported more than 10 millions customers had been affected, but Prosper said at the time its investigation into the exact number was ongoing.
On Nov. 26, the company completed its investigation. In the end, the company found 13.1 million individuals were affected, a spokesperson told American Banker. The company began sending notifications to affected customers on December 9.
A massive breach at 700Credit , a provider of credit reports and compliance solutions for automotive dealers, exposed the data of millions of consumers.
The National Automobile Dealers Association (NADA) coordinated with the Federal Trade Commission to allow 700Credit to file a consolidated breach notice on behalf of affected dealers to reduce the regulatory burden.
The credit reporting agency suffered a breach involving a third-party application, exposing millions of files.
A ransomware attack on Marquis Software Solutions, a vendor providing marketing and compliance services to financial institutions, cascaded across the community banking sector .
The risk management data and software company, which provides anti-money laundering and other services to financial institutions, experienced a breach stemming from a software development platform.
This Connecticut-based credit union suffered a breach affecting a significant portion of its membership.
The cryptocurrency exchange faced an extortion attempt following a breach caused by insider wrongdoing.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
