CSIDB logo
Incident

Community Bank

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 00:55

Linked entities

Victim
Community Bank
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
May 2026
Disclosed
May 2026
Resolved
Pending

Summary

Community Bank, which operates in Pennsylvania, Ohio, and West Virginia, disclosed a cybersecurity incident that exposed customers’ names, dates of birth, and Social Security numbers after detecting an unauthorized artificial intelligence‑based software application had accessed the data. The bank said the exposure appeared to result from an employee uploading customer information to an online AI chatbot, potentially sharing it with the chatbot’s provider, though it did not specify how many customers were affected or which application was involved. It stated it is evaluating the affected data and sending notifications in line with applicable laws, while its chief executive did not respond to a request for comment.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 7, 2026, Community Bank submitted an 8‑K filing to the U.S. Securities and Exchange Commission in which it disclosed a cybersecurity incident involving the exposure of customers’ personal data. The filing stated that the exposure was detected as a result of the bank’s use of an unauthorized artificial intelligence‑based software application. According to the bank’s disclosure, the incident was reported because of the volume and sensitive nature of the non‑public information that had been compromised. The article notes that the exact mechanism of the exposure remains unclear, but the language in the filing suggests that an employee of Community Bank may have uploaded customer data to an online AI chatbot, potentially allowing the chatbot’s provider to access that information. Community Bank did not reveal the total number of customers whose data was affected, nor did it identify the specific AI application that was involved in the incident.

The exposed data included customers’ names, dates of birth, and Social Security numbers, which constitute highly sensitive personal information. In response to the incident, Community Bank indicated that it is evaluating the customer data that was affected and is sending notifications to individuals in accordance with applicable state and federal data breach laws. The bank also noted that it is cooperating with regulators as part of its standard breach response process. Community Bank operates branches in Pennsylvania, Ohio, and West Virginia, and the incident potentially affects customers across those states. The bank’s chief executive, John Montgomery, did not provide a comment when approached by TechCrunch for a statement regarding the disclosure. The Register was the first outlet to report the security lapse, and TechCrunch published its coverage of the incident on May 12, 2026. No further technical details about the unauthorized AI application or the specific chatbot service were made available in the sources consulted.

Sources

Sources available to members: 1 source.

CSIDB