Community Bank Data Breach Caused by Unauthorized AI Application

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Community Bank, operating in Pennsylvania, Ohio, and West Virginia, disclosed a data breach after an employee uploaded sensitive customer information—including names, birth dates, and Social Security numbers—to an unauthorized AI-based application. The incident exposed private data, prompting regulatory disclosure and customer notifications due to legal and privacy concerns.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event explicitly mentions the use of an unauthorized AI-based software application that caused exposure of sensitive personal data, which is a violation of privacy and data protection rights. This meets the criteria for an AI Incident because the AI system's use directly led to harm (violation of rights and potential harm to individuals). The incident is not merely a potential risk but a realized harm, and thus it cannot be classified as a hazard or complementary information. It is not unrelated because the AI system's involvement is central to the incident.[AI generated]
AI principles
AccountabilityPrivacy & data governance

Industries
Financial and insurance services

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Severity
AI incident

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

U.S. bank disclose security lapse after sharing customer data with AI app

2026-05-12
TechCrunch
Why's our monitor labelling this an incident or hazard?
The event explicitly mentions the use of an unauthorized AI-based software application that caused exposure of sensitive personal data, which is a violation of privacy and data protection rights. This meets the criteria for an AI Incident because the AI system's use directly led to harm (violation of rights and potential harm to individuals). The incident is not merely a potential risk but a realized harm, and thus it cannot be classified as a hazard or complementary information. It is not unrelated because the AI system's involvement is central to the incident.
Thumbnail Image

US bank reports itself after slinging customer data at 'unauthorized AI app'

2026-05-12
TheRegister.com
Why's our monitor labelling this an incident or hazard?
The bank's use of an unauthorized AI application to process sensitive customer data directly led to a data breach involving personal information protected by law. This constitutes a violation of legal obligations and a harm to customers' privacy rights. The AI system's unauthorized use and the resulting exposure of sensitive data meet the criteria for an AI Incident under the framework, as the AI system's use directly led to a breach of obligations under applicable law protecting fundamental rights.
Thumbnail Image

Bank Employee Drops Customer Data Into AI Chatbot, Exposes Thousands

2026-05-14
Gadget Review
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (an AI chatbot) that was used improperly by a bank employee, leading to the exposure of sensitive personal data of thousands of customers. This exposure constitutes a violation of privacy rights and data protection laws, which falls under harm category (c) - violations of human rights or breach of obligations under applicable law. The harm is realized, not just potential, as the data was exposed. The AI system's use was unauthorized and led directly to the incident. Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

U.s. Bank Disclose Security Lapse After Sharing Customer Data With Ai App

2026-05-12
Breaking News, Latest News, US and Canada News, World News, Videos
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (an unauthorized AI-based application or chatbot) that was used to process or handle customer data, resulting in a security lapse and exposure of sensitive personal information. This exposure constitutes a violation of privacy rights and applicable laws protecting personal data, which is a recognized harm under the AI Incident definition. The bank's disclosure confirms the AI system's involvement in causing the harm. Hence, the event is classified as an AI Incident.
Thumbnail Image

Community Bank customer data exposed via unauthorized AI software

2026-05-13
SC Media
Why's our monitor labelling this an incident or hazard?
The incident involves the use of an AI system (an AI chatbot) that led to unauthorized exposure of sensitive personal data, which is a clear harm under the category of violations of human rights and legal obligations protecting personal data. The harm has already occurred as the data was exposed, and the bank is notifying affected customers. Therefore, this qualifies as an AI Incident because the AI system's use directly caused harm through data exposure.
Thumbnail Image

Community Bank discloses security lapse after unauthorized AI app exposure

2026-05-15
Crypto Briefing
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (unauthorized AI software) whose use by an employee directly caused a data breach exposing sensitive customer information. This breach constitutes a violation of privacy rights and regulatory obligations, which falls under harm category (c) - violations of human rights or breach of legal obligations protecting fundamental rights. The harm has already occurred and is materialized, with regulatory notifications and potential legal consequences underway. Therefore, this is classified as an AI Incident.
Thumbnail Image

The invisible flaw of AI: Community Bank exposes sensitive data

2026-05-16
The Cryptonomist
Why's our monitor labelling this an incident or hazard?
The incident involves an AI system explicitly mentioned as being used by an employee without authorization, leading to the exposure of sensitive personal data. This constitutes a violation of privacy rights and regulatory obligations, which falls under harm category (c) - violations of human rights or breach of applicable law protecting fundamental rights. The harm has already occurred, as sensitive data was improperly exposed, and regulatory notifications have been initiated. The event is not merely a potential risk but a realized incident caused by the AI system's use, thus classifying it as an AI Incident.