Threat actors have claimed responsibility for a significant data breach targeting HSBC USA, alleging the theft and subsequent leak of a large trove of personally identifiable information (PII) and sensitive financial records belonging to the bank's customers. The compromised data reportedly includes full names, addresses, Social Security numbers, dates of birth, phone numbers, bank account numbers, account balances, and transaction histories. Multiple sources indicate that the data was posted on prominent data leak forums, with early analysis by independent researchers suggesting the leaked samples appear legitimate, though the full scope and authenticity remain under investigation. Security experts warn that the exposure of such comprehensive PII and financial details could enable a range of fraudulent activities, including identity theft, unauthorized account access, SIM swapping, and spearphishing attacks.
HSBC USA has publicly denied that a breach occurred, stating that internal investigations have found no evidence of compromised systems or service providers. Despite the bank's denial, cybersecurity researchers and industry analysts emphasize the severe risks posed by the alleged leak, urging financial institutions to strengthen authentication mechanisms, enhance account recovery processes, and promptly notify potentially affected customers. The incident has raised concerns about the adequacy of data protection measures in the banking sector and highlights the urgent need for robust security controls to prevent large-scale identity and financial fraud.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Hackers subsequently leaked the purported HSBC USA customer data online, escalating the incident from a breach claim to public exposure of the allegedly stolen records.
Threat actors publicly claimed to have breached HSBC USA and to possess customer data, including personally identifiable information and financial or transaction records. Multiple reports describe the same alleged incident and data exposure claim.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberpress.org
Open sourcescworld.com
Open sourcecybernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.