Cyber Security News

Hackers Allegedly Claim Breach Of HSBC USA Customers’ Records Including Financial Details

A threat actor has claimed responsibility for breaching HSBC USA, alleging possession of a vast database containing sensitive customer personal identifiable information (PII) and financial details.

The hacker posted screenshots and data samples on a dark web leak forum, asserting the breach involved coordinated efforts to extract records from the bank’s systems.

This incident, reported on October 28, 2025, has raised alarms in the cybersecurity community amid HSBC’s ongoing challenges in the U.S. market.

The alleged stolen database contains full names, addresses, Social Security numbers (SSNs), dates of birth, phone numbers, email addresses, transaction histories, stock orders, and bank account numbers.

HSBC USA Customers Records

Researchers analyzed a provided sample and found indications of legitimacy, with the data appearing recent, potentially from just weeks prior, and possibly targeting corporate or institutional clients rather than retail ones.

HSBC USA has largely exited the U.S. mass retail banking sector, which could explain its focus on business accounts.

The attached screenshot of the forum post corroborates the claim, showing an “Exclusive HSBC USA DB” with promises of validation and no free distribution.

HSBC’s Response and Implications

HSBC has acknowledged a recent denial-of-service (DoS) attack but has firmly denied any customer data compromise in its official statements.

The bank is investigating claims through third-party vendor access points and has strengthened defenses with enhanced authentication and monitoring.

No confirmed financial losses have occurred, but experts warn of risks such as identity theft, spear-phishing, and social engineering attacks exploiting the exposed details.

Regulatory bodies, including the U.S. Department of the Treasury, are monitoring the situation closely. This breach highlights vulnerabilities in financial third-party ecosystems, potentially damaging HSBC’s reputation and prompting client attrition.

Customers are urged to monitor accounts, enable two-factor authentication, and change passwords immediately to mitigate potential fallout.

As investigations continue, the full scope remains unclear, but the event underscores the persistent threats facing global banks.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Chrome to Alert Users “Always Use Secure Connections” While Opening Public HTTP Sites

Google has announced a significant security initiative that will fundamentally change how Chrome handles unsecured…

32 seconds ago

Windows Accessibility Flaw Allows Stealthy Persistence and Lateral Movement via Narrator DLL Hijack

A persistent vulnerability related to DLL hijacking has been identified in the Narrator accessibility tool,…

2 hours ago

CISA Warns of Dassault Systèmes Vulnerabilities Actively Exploited in Attacks

CISA has added two critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso to its Known Exploited…

3 hours ago

Google Wear OS Message App Vulnerability Let Any Installed App To Send SMS Behalf Of User

A vulnerability in Google Messages on Wear OS devices allows any installed app to silently…

4 hours ago

New Beast Ransomware Actively Scans for Active SMB Port from Breached System to Spread Across Network

The Beast ransomware group has emerged as a significant threat in the cybersecurity landscape, evolving…

4 hours ago

Microsoft Sued for Allegedly Misleading Millions to Subscribe for Microsoft 365 Subscriptions

Australia's competition regulator has filed legal proceedings against Microsoft for allegedly misleading approximately 2.7 million…

5 hours ago