Were you recently affected by a data breach?

Quontic Bank Data Breach

Quontic Bank, a New York-based digital community bank, began notifying customers on July 17, 2026 of a data security incident involving unauthorized access to account information and, separately, former employees retaining customer records.

Quontic Bank
Date of Breach: Data accessed/retained May 28, 2026; notifications began July 16-17, 2026
CAU logo

Who was affected:

Clients of Quontic Bank

Impacted Data:

Names, financial account information, additional personal information not fully specified in the public notice

Quontic Bank, a New York-based digital community bank headquartered in Astoria, New York, began notifying customers on July 17, 2026 that their information was affected by a data security incident. Quontic Bank has disclosed the incident in two parts: notifications sent directly to customers describe unauthorized access to names and financial account information, while a separate notice filed with the California Attorney General’s Office on July 17, 2026 describes former employees retaining certain customer records after leaving the company. Companies that collect and store personal information have a responsibility to protect it with reasonable security measures.

Quontic Bank’s Data Breach Investigation

Quontic Bank, a digital community bank headquartered in Astoria, New York, has notified affected individuals of a data security incident. Quontic Bank is known for its digital banking platform, adaptive mortgage lending products, and community development financing.

According to notifications sent to affected individuals, an unauthorized party accessed customer data on May 28, 2026, and Quontic Bank began sending notice letters to those affected on July 17, 2026. Separately, according to a sample notice filed with the California Attorney General’s Office, Quontic Bank became aware on May 28, 2026 that two former employees retained certain customer records after departing the company. The bank sent notification letters describing that issue dated July 16, 2026, and reported it to the California Attorney General’s Office on July 17, 2026. The bank states it has been working with law enforcement and outside authorities to investigate and reports that, based on its review to date, there is no evidence the retained information has been used to commit identity theft or fraud. It describes the notice as a precautionary measure rather than confirmation of misuse, and is offering affected customers complimentary credit monitoring and identity restoration services through Experian for a defined period.

The specific number of individuals impacted has not been publicly disclosed at this time, nor has the company disclosed the full cause of either incident. Banking institutions are frequent targets for both external attackers and internal data-handling failures because the information they hold, names paired with financial account details, can be used directly for fraud, unauthorized transactions, and identity theft. Financial institutions like Quontic Bank routinely provide employees with access to sensitive customer data as part of day-to-day banking operations, which makes offboarding procedures, revoking system access and confirming the return or deletion of any retained records, a critical control point. When that process fails, even without evidence of external misuse, customers are still exposed to a real risk that their information could later be used improperly, which is why notification laws generally require disclosure regardless of whether fraud has yet occurred.

State and federal data breach notification laws typically require notice to affected individuals and, in cases involving a sufficient number of records or resident state requirements, to state attorneys general without unreasonable delay. The gap seen here, roughly seven weeks between the date data was accessed or retained (May 28, 2026) and the date notification letters went out (July 16 and 17, 2026), falls within a range commonly seen once a company completes its internal investigation and any required forensic review before notifying customers, though it is ultimately Quontic Bank’s own timeline, not a fact established by any regulator’s findings referenced here.

If you received a letter from Quontic Bank about either of these incidents, or believe your information may have been affected, it is important to understand your rights and the potential legal options available to you.

When Did This Breach Occur?

Quontic Bank has stated that unauthorized access to customer data occurred on May 28, 2026, with notification letters sent beginning July 17, 2026. Separately, Quontic Bank states it became aware on May 28, 2026 that two former employees had retained certain customer records after leaving the company, with notification letters for that issue dated July 16, 2026 and reported to the California Attorney General’s Office on July 17, 2026.

What Information Was Breached?

Quontic Bank has disclosed that the information involved in the unauthorized access included names and financial account information. In the separate former-employee matter, the notice confirms customer names were involved, along with unspecified additional information described only in a placeholder field in the sample notice reviewed. The company has not publicly disclosed the full cause of either incident or the total number of individuals affected. Because Quontic Bank is a financial institution, records its employees would typically have access to could include account numbers, balances, transaction history, or other sensitive financial details, though the bank has not publicly confirmed which specific categories were involved in the former-employee matter.

What You Can Do

If you received a notice from Quontic Bank about either incident, consider taking the following steps:

  • Review the breach notice carefully and keep a copy for your records.
  • Enroll in any free credit monitoring or identity protection services offered by Quontic Bank, including the complimentary Experian credit monitoring and identity restoration services mentioned in the former-employee notice.
  • Monitor your bank and credit card statements closely for unauthorized transactions.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus (Equifax, Experian, and TransUnion).
  • Change online banking passwords and enable multi-factor authentication where available.
  • Report any suspicious account activity to Quontic Bank directly using the contact information in your notice.

File a Data Breach Lawsuit Against Quontic Bank

If you were notified that your information was exposed in either Quontic Bank incident, you may have legal options. Financial institutions have a duty to reasonably safeguard the personal and financial information entrusted to them by customers, and a heightened responsibility to control access to customer records, including ensuring that departing employees cannot retain sensitive data after their employment ends.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 8, 2025 to August 27, 2025 (discovered July 16, 2026)
Date of Breach: September 5, 2025 (discovered July 6, 2026)
Date of Breach: On or about April 7, 2026 (ransomware detected)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.