Quontic Bank, a New York-based digital community bank headquartered in Astoria, New York, began notifying customers on July 17, 2026 that their information was affected by a data security incident. Quontic Bank has disclosed the incident in two parts: notifications sent directly to customers describe unauthorized access to names and financial account information, while a separate notice filed with the California Attorney General’s Office on July 17, 2026 describes former employees retaining certain customer records after leaving the company. Companies that collect and store personal information have a responsibility to protect it with reasonable security measures.
Quontic Bank’s Data Breach Investigation
Quontic Bank, a digital community bank headquartered in Astoria, New York, has notified affected individuals of a data security incident. Quontic Bank is known for its digital banking platform, adaptive mortgage lending products, and community development financing.
According to notifications sent to affected individuals, an unauthorized party accessed customer data on May 28, 2026, and Quontic Bank began sending notice letters to those affected on July 17, 2026. Separately, according to a sample notice filed with the California Attorney General’s Office, Quontic Bank became aware on May 28, 2026 that two former employees retained certain customer records after departing the company. The bank sent notification letters describing that issue dated July 16, 2026, and reported it to the California Attorney General’s Office on July 17, 2026. The bank states it has been working with law enforcement and outside authorities to investigate and reports that, based on its review to date, there is no evidence the retained information has been used to commit identity theft or fraud. It describes the notice as a precautionary measure rather than confirmation of misuse, and is offering affected customers complimentary credit monitoring and identity restoration services through Experian for a defined period.
The specific number of individuals impacted has not been publicly disclosed at this time, nor has the company disclosed the full cause of either incident. Banking institutions are frequent targets for both external attackers and internal data-handling failures because the information they hold, names paired with financial account details, can be used directly for fraud, unauthorized transactions, and identity theft. Financial institutions like Quontic Bank routinely provide employees with access to sensitive customer data as part of day-to-day banking operations, which makes offboarding procedures, revoking system access and confirming the return or deletion of any retained records, a critical control point. When that process fails, even without evidence of external misuse, customers are still exposed to a real risk that their information could later be used improperly, which is why notification laws generally require disclosure regardless of whether fraud has yet occurred.
State and federal data breach notification laws typically require notice to affected individuals and, in cases involving a sufficient number of records or resident state requirements, to state attorneys general without unreasonable delay. The gap seen here, roughly seven weeks between the date data was accessed or retained (May 28, 2026) and the date notification letters went out (July 16 and 17, 2026), falls within a range commonly seen once a company completes its internal investigation and any required forensic review before notifying customers, though it is ultimately Quontic Bank’s own timeline, not a fact established by any regulator’s findings referenced here.
If you received a letter from Quontic Bank about either of these incidents, or believe your information may have been affected, it is important to understand your rights and the potential legal options available to you.
When Did This Breach Occur?
Quontic Bank has stated that unauthorized access to customer data occurred on May 28, 2026, with notification letters sent beginning July 17, 2026. Separately, Quontic Bank states it became aware on May 28, 2026 that two former employees had retained certain customer records after leaving the company, with notification letters for that issue dated July 16, 2026 and reported to the California Attorney General’s Office on July 17, 2026.
What Information Was Breached?
Quontic Bank has disclosed that the information involved in the unauthorized access included names and financial account information. In the separate former-employee matter, the notice confirms customer names were involved, along with unspecified additional information described only in a placeholder field in the sample notice reviewed. The company has not publicly disclosed the full cause of either incident or the total number of individuals affected. Because Quontic Bank is a financial institution, records its employees would typically have access to could include account numbers, balances, transaction history, or other sensitive financial details, though the bank has not publicly confirmed which specific categories were involved in the former-employee matter.
What You Can Do
If you received a notice from Quontic Bank about either incident, consider taking the following steps:
- Review the breach notice carefully and keep a copy for your records.
- Enroll in any free credit monitoring or identity protection services offered by Quontic Bank, including the complimentary Experian credit monitoring and identity restoration services mentioned in the former-employee notice.
- Monitor your bank and credit card statements closely for unauthorized transactions.
- Consider placing a fraud alert or credit freeze with the major credit bureaus (Equifax, Experian, and TransUnion).
- Change online banking passwords and enable multi-factor authentication where available.
- Report any suspicious account activity to Quontic Bank directly using the contact information in your notice.
File a Data Breach Lawsuit Against Quontic Bank
If you were notified that your information was exposed in either Quontic Bank incident, you may have legal options. Financial institutions have a duty to reasonably safeguard the personal and financial information entrusted to them by customers, and a heightened responsibility to control access to customer records, including ensuring that departing employees cannot retain sensitive data after their employment ends.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.