Lee Bank recently notified a customer that a processing error caused an image of a check tied to their account to become viewable by another bank customer, exposing their account number and name. While the bank has described this as an isolated processing error rather than a hacking incident, any unauthorized exposure of account information can create risk for the affected customer and is the kind of incident financial institutions are expected to prevent through proper internal controls.
Lee Bank’s Data Breach Investigation
Lee Bank, a Massachusetts-based community bank, sent a notification letter informing a customer that a check related to their account had been erroneously viewable by another Lee Bank customer due to a processing error. According to the letter, this exposed the account number and the name associated with the account. Lee Bank stated that the image was immediately removed once the error was identified and that the underlying transaction was corrected.
Unlike many data breaches that stem from a hacking incident or a ransomware attack, this incident appears to have originated from an internal processing error within the bank’s check-handling systems rather than from an external cyberattack. Lee Bank emphasized in its letter that the exposure was limited to one other bank customer viewing the check image, and that it has no indication that any fraudulent activity has occurred on the affected account as a result.
Financial institutions like Lee Bank process enormous volumes of check images and account records every day, and even a single misrouted or mislabeled item can expose a customer’s account number and personal information to someone who has no legitimate reason to see it. While this type of processing error is generally less severe than a large-scale network intrusion, it still represents a lapse in the safeguards banks are expected to maintain around sensitive financial records, since an account number combined with an accountholder’s name can, in the wrong hands, be used to attempt fraudulent transactions or social-engineering schemes targeting the account.
Under Massachusetts law, financial institutions and other entities that experience an unauthorized acquisition or use of unencrypted personal information are generally required to notify affected residents, regardless of whether the underlying cause was external hacking or an internal processing error. This notification requirement exists precisely because the risk to the affected customer, potential misuse of exposed account information, does not depend on how the exposure occurred. Customers who receive this kind of notice are encouraged to treat the exposure seriously even when a bank characterizes the underlying cause as low-risk, since it can be difficult for an outside party to independently verify how limited the actual exposure was.
Customers affected by any exposure of their bank account number should also be alert to phishing attempts that reference the incident, since scammers sometimes use word of a bank’s data exposure to send fraudulent emails or texts posing as the bank itself in an attempt to extract additional account credentials or personal information. Any communication asking a customer to verify account details or click a link should be treated with suspicion, and customers should instead contact their bank directly using a known phone number to confirm the legitimacy of any such request.
When Did This Breach Occur?
Lee Bank’s notification letter does not specify the exact date on which the processing error occurred or when it was discovered. The letter states only that the exposure was identified and that the check image was immediately removed and the transaction corrected once the error was identified.
What Information Was Breached?
According to Lee Bank’s notification letter, the exposed information was limited to the affected customer’s account number and the name associated with the account, as reflected in the check image that was erroneously made viewable to another bank customer. The bank stated that no other personal or account information on file at Lee Bank was compromised as a result of this specific incident.
What You Can Do
Lee Bank has stated that it does not believe any fraudulent activity has occurred as a result of this incident, but the bank recommends that affected customers take precautionary steps, including:
- Continue to monitor your bank account through regular statement review and online banking
- Immediately report any unrecognized or unusual activity on your account to Lee Bank
- Consider placing a free security freeze on your credit reports with Equifax, Experian, and TransUnion
- Obtain a copy of any police report filed in connection with this incident if you believe you have been a victim of identity theft
File a Data Breach Lawsuit Against Lee Bank
If you received a data breach notification letter from Lee Bank, you may be entitled to compensation. Financial institutions that collect and store sensitive account information have a legal obligation to protect it, and when that obligation is not met, affected individuals may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.