Data breach
Truist Bank
- Records
- 76,313
- Breach date
- 14 February 2024Estimated
- Added
- 15 June 2026
What was exposed
2 types of data · 6 more reported
- Email addresses76,313
- Phone numbers13,376
- Social security numbersReported, not counted
- Driving licence numbersReported, not counted
- Government IDsReported, not counted
- NamesReported, not counted
- Home addressesReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Truist Bank customers were affected by a 2024 data breach at Financial Business and Consumer Solutions (FBCS), a third-party debt collection agency that provided services to the bank. According to a notification Truist filed with the California Attorney General, an unauthorized actor had the ability to view or acquire information on FBCS's network between February 14 and February 26, 2024. FBCS discovered the unauthorized access on February 26 and launched an investigation with outside computer forensics specialists. Truist said the incident did not impact its own systems or network.
Our investigation team estimates that this listing covers 76,313 records tied to Truist Bank, with an email address present in each record and phone numbers in 13,376 of them. No actor has publicly claimed responsibility for this listing. Separately, FBCS told the Maine Attorney General's office that the broader incident affected more than 4.2 million people across all of its clients, according to reporting by Banking Dive.
Breach Timeline
February 14 to 26, 2024: Per Truist's notification, an unauthorized actor had the ability to view or acquire certain information on FBCS's network. FBCS discovered the unauthorized access on February 26 and launched an investigation.
April 2024: FBCS warned that roughly 1.9 million people were affected by the breach, per Banking Dive.
August 29, 2024: FBCS filed for Chapter 7 bankruptcy protection in federal court in Pennsylvania.
September 9, 2024: Truist sent data breach notification letters to affected customers, per its filing with the California Attorney General.
October 2024: Banking Dive reported that FBCS's updated notification to the Maine Attorney General put the total number of affected people at more than 4.2 million.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (76,313 records) and phone numbers (13,376 records).
Truist's official notice letter, filed with the California Attorney General, states that the information impacted may also include consumer name, address, account number, date of birth, and Social Security number, and that the types of information vary per person. FBCS's filings also identified driver's license numbers and other state identification information among the exposed data, according to Banking Dive.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Because email addresses and phone numbers were exposed, affected people may face an elevated risk of phishing emails, smishing text messages, and social engineering attempts. Fraudsters can pose as a bank, debt collector, or credit bureau and use real personal details to sound convincing. Where Social Security numbers, dates of birth, or account numbers were involved, the risk extends to identity theft, fraudulent loan or credit card applications, and unauthorized access to existing accounts. Anyone whose information was included should treat unexpected messages about debts, accounts, or "security issues" with suspicion and verify them through official channels rather than links or phone numbers in the message.
What Is Truist Bank Doing in Response?
In its September 2024 notice, Truist said it promptly sought information from FBCS after learning of the incident and that FBCS took steps to secure its systems and engaged outside computer forensics specialists. Truist stated the issue occurred on FBCS's systems and did not affect Truist systems or its network. The bank arranged to offer affected customers two years of free credit monitoring and identity protection services through Experian's CSIdentity, with enrollment required by December 20, 2024. Truist also set up a dedicated phone line, 1-844-487-8478, for customer questions. Banking Dive reported that Truist declined to comment beyond its letter.
What Should You Do If You Were Affected?
If you received a notice from Truist about this incident, enroll in the free credit monitoring offer before the stated deadline and check the enrollment terms. Review your credit reports at annualcreditreport.com for accounts or inquiries you do not recognize. Consider placing a fraud alert, or a stronger security freeze, with all three credit bureaus: Equifax, Experian, and TransUnion. Watch your bank and credit card statements for unauthorized activity and report anything suspicious to the institution immediately. If you believe your identity has been stolen, the Federal Trade Commission provides a recovery guide at identitytheft.gov. Be alert for phishing emails or texts referencing Truist or a debt collection matter, and do not click links or share information in unexpected messages.
