Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Two former employees retained certain Quontic Bank customer records after departing the company. [2]
Impact
Customer records retained by two former Quontic employees; affected fields varied by individual. [1][3]
Documented data types include:
- Names — The sample notice states that names were involved; other fields varied by recipient. [1][3]
- Social Security numbers — Massachusetts incident report 2026-1176 marks Social Security numbers as breached. [1][3]
A cited record reports 111 individuals (Massachusetts residents affected according to incident report 2026-1176; not a national total; as of 2026-07-17). [1][3]
A cited record reports 40 individuals (Approximate number of Rhode Island residents who may be impacted; not a national total). [1]
Two former Quontic employees retained certain customer records after leaving the company. [1]
Timeline
Discovery
Date Quontic says it became aware that two former employees retained customer records.
[1]Documented event
Date printed on the California sample notice.
[1]Public disclosure
Date reported to Massachusetts OCA and listed by the California Attorney General.
[3]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Quontic said its investigation found no evidence that the information was used to commit identity theft or fraud. Quontic offered affected recipients complimentary Experian credit monitoring and identity-restoration services. Quontic worked with authorities and reviewed its existing policies and procedures. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
