Quick Facts

  • Community Bank disclosed exposure of customer names, birth dates, and Social Security numbers through unauthorized AI application use
  • Bank filed SEC disclosure on May 7 due to volume and sensitive nature of exposed data, with no operational impact reported
  • Incident highlights growing regulatory scrutiny of AI security risks as SEC shifts examination priorities from crypto to AI threats

Community Bank disclosed a cybersecurity incident that exposed customers’ Social Security numbers and personal information through unauthorized artificial intelligence software. The Pennsylvania-based bank, which operates across Pennsylvania, Ohio, and West Virginia, filed an 8-K disclosure with the Securities and Exchange Commission on May 7.

The bank detected exposure of customer names, dates of birth, and Social Security numbers due to use of “an unauthorized artificial intelligence-based software application.” Community Bank said it filed the disclosure “due to the volume and sensitive nature of the non-public information” but provided no details about which AI application was involved or how many customers were affected.

The incident appears to involve an employee uploading customer data to an online AI chatbot, potentially exposing the information to the chatbot provider. Banks face increasing risks from employees using unapproved generative AI tools to process sensitive customer data.

Community Bank confirmed no operational impact occurred. Customers maintained access to accounts and payment services throughout the incident. The bank said it continues communicating with banking and financial regulators while pursuing remediation efforts.

The disclosure reflects a significant regulatory shift. The SEC’s 2026 examination priorities show cybersecurity and AI concerns have displaced cryptocurrency as the dominant risk topic. AI moved from an emerging fintech area to a clear operational risk linked to cybersecurity and internal use for critical functions.

Social Security numbers represent the most sensitive customer data that organizations store under federal and state laws. The Colorado AI Act takes effect June 30, targeting high-risk AI systems that influence decisions like loan approvals. The legislation requires risk management programs and impact assessments for financial institutions.

Treasury Secretary Scott Bessent said U.S. financial and technology companies are “working on their resiliency” against AI threats, including concerns about AI deployment for hacking bank accounts. The banking industry faces mounting pressure to establish compliance frameworks for AI systems amid intensified regulatory scrutiny.

April 2026 saw multiple major security incidents involving third-party vendors and AI productivity tools. Attackers increasingly target trusted third parties rather than direct system breaches, creating new vulnerability vectors for financial institutions.

Read more: US bank discloses security lapse after sharing customer data with AI app

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.