Techcrunch Community Bank Data Breach Exposes Sensitive Customer Information via Unauthorized AI Software
Article Content
- •Community Bank disclosed a data breach involving unauthorized AI software on May 7, 2026.
- •Sensitive customer data, including Social Security numbers, was exposed, affecting customers in three states.
- •Legal investigations are underway for a potential class action lawsuit for affected individuals.
Community Bank has reported a data breach involving the unauthorized use of AI software that exposed sensitive customer information, including names, Social Security numbers, and dates of birth. The breach was disclosed in an 8-K filing with the SEC on May 7, 2026, after the bank detected the exposure on May 5. The unauthorized AI application was not specified, but it raises concerns about potential third-party data access. Community Bank is currently investigating the incident and notifying affected customers as required by law. The breach affects customers in southwestern Pennsylvania, southeastern Ohio, and northwestern West Virginia. Legal representatives are exploring the possibility of a class action lawsuit for those impacted. No operational impact on banking services was reported, and the bank is committed to enhancing data protection measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track CB Financial Services in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…