Community Bank disclosed a security incident after customer information was exposed through use of an unauthorized AI-based software application, according to a filing with the U.S. Securities and Exchange Commission. The bank said the compromised non-public data included customer names, dates of birth, and Social Security numbers, and that it reported the matter because of the volume and sensitivity of the information involved. Reporting indicates the lapse may have occurred when customer data was uploaded to an online AI chatbot or similar service, though the bank has not identified the application or explained the exact mechanism.
The bank said the incident did not disrupt operations or prevent customers from accessing accounts or payment services, but it is still assessing the scope of affected data and notifying impacted individuals as required by law. Community Bank is also communicating with banking and financial regulators and pursuing remediation to prevent a recurrence. The number of affected customers remains undisclosed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
BWH Hotels notified customers and publicly disclosed that a third-party data breach affected guest reservation information across its hotel brands. The company warned affected guests to watch for phishing or scam attempts using stolen reservation details.
On May 7, 2026, Community Bank disclosed in an SEC 8-K that customer personal data was exposed through use of an unauthorized AI-based software application. The bank said the exposed information included names, dates of birth, and Social Security numbers, and that it was assessing impact, notifying affected customers, and coordinating with regulators.
On April 22, 2026, BWH Hotels discovered the intrusion affecting its reservation web application. The company said it took the application offline, revoked unauthorized access, and engaged external cybersecurity experts to investigate and strengthen safeguards.
BWH Hotels said an intruder gained unauthorized access to a web application storing guest reservation information, with exposed records dating back to October 14, 2025. The affected data included guest contact and reservation details, but not payment or banking information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcetheregister.com
Open sourcetechcrunch.com
Open sourcetechcrunch.com
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.