[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhu9e6esG5HJgmjiakZNRTGakuG-I7J3DN5_EZuuwg3A":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":27,"source":28,"isVerified":4,"isSpamList":29,"isSensitive":4,"severity":30,"processingStatus":31,"logoUrl":32,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a671353d80922f6117e5ce7","WesternAllianceBank2024","Western Alliance Bank 2024 Data Breach","western-alliance-bank-2024","westernalliancebancorporation.com",{"name":12,"sector":13,"country":14,"website":10},"Western Alliance Bank","Financial Services","United States","2024-10-12T00:00:00.000Z","2026-07-27T08:14:11.471Z",21899,[19,20,21,22,23,24,25,26],"Personal information","Names","Social Security numbers","Dates of birth","Financial account numbers","Driver's license numbers","Tax identification numbers","Passport numbers","\u003Cp>\u003Cstrong>The Western Alliance Bank 2024 data breach\u003C\u002Fstrong> resulted from exploitation of a then-unknown vulnerability in third-party secure file-transfer software used by the bank. An unauthorized actor accessed a limited portion of the bank's systems and obtained copies of files from October 12 through October 24, 2024. Western Alliance learned of possible access on January 27, 2025, and notified law enforcement.\u003C\u002Fp>\n\u003Cp>A file review determined on February 21 that names and Social Security numbers were present, with dates of birth, financial-account numbers, driver's-license numbers, tax-identification numbers, and passports for some people. Source-linked regulatory records report 21,899 affected individuals. LeakData uses that figure for pwnCount and totalRecords; no customer rows were imported, so importedRecordCount is zero.\u003C\u002Fp>\n\u003Ch2>How Was the Western Alliance Bank Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary evidence is Western Alliance Bank's consumer letter published in California and Massachusetts regulatory files. On the bank's behalf, the document directly describes the third-party software vulnerability, access and file-acquisition period, discovery and data-review dates, confirmed information fields, law-enforcement notification, and identity-protection service offered.\u003C\u002Fp>\n\u003Cp>Maine and other state attorney-general records also support the notification process. Claim Depot connects those official files and publishes the nationwide total of 21,899 people and state subsets in structured form. The sources align on the event period, third-party transfer software, copying of files, and core data classes.\u003C\u002Fp>\n\u003Ch2>What Happened From October 12 Through October 24, 2024?\u003C\u002Fh2>\n\u003Cp>Secure file-transfer software used by Western Alliance and many other organizations contained a previously unknown vulnerability. An unauthorized actor exploited it in October and accessed a limited portion of the bank's systems. The investigation determined that the actor acquired certain files from October 12 through October 24.\u003C\u002Fp>\n\u003Cp>The bank learned of possible access on January 27, 2025, began reviewing the files, and determined on February 21 that personal information was present. A secondary source reports a responsibility claim by the CL0P group, while the consumer letter does not name an actor or attribute ransomware. LeakData treats the third-party vulnerability and file acquisition as verified without presenting the group claim as conclusive attribution.\u003C\u002Fp>\n\u003Ch2>What Identity Information Was Affected?\u003C\u002Fh2>\n\u003Cp>The notice lists names and Social Security numbers as confirmed core fields. Dates of birth, driver's-license numbers, tax-identification numbers, and passports may also have been present when a person had provided them to the bank. The same combination should not be assumed for every affected individual because scope varied by customer and file.\u003C\u002Fp>\n\u003Cp>A combination of SSN, tax ID, birth date, and government document creates long-term risk of fraudulent credit, tax fraud, business-identity misuse, and targeted phishing. When a passport or driver's license was involved, renewal and misuse-reporting options from the issuing authority may be worth reviewing. Document images or verification codes should not be shared through unexpected bank-branded messages.\u003C\u002Fp>\n\u003Ch2>How Was Financial-Account Information Affected?\u003C\u002Fh2>\n\u003Cp>The bank said some files may have contained financial-account numbers. This field may enable account-related fraud, fraudulent payment requests, or social engineering that targets a customer with accurate account context. The public letter does not identify the account type, financial institution name, or whether an account remained open at the time of the event.\u003C\u002Fp>\n\u003Cp>The source does not specifically confirm payment-card numbers, expiration dates, CVVs, PINs, online-banking passwords, routing numbers, balances, or transaction histories. LeakData does not add those fields to dataClasses. Recipients should enable activity alerts through the bank's official application and report unfamiliar transfers, payees, or profile changes directly to the institution.\u003C\u002Fp>\n\u003Ch2>How Many People Were Affected and Was Misuse Observed?\u003C\u002Fh2>\n\u003Cp>The source connecting regulatory records reports 21,899 affected people, the figure used for pwnCount and totalRecords. Subsets include 1,222 Texas, 539 Washington, 41 New Hampshire, 17 Massachusetts, and six Maine residents. Those state figures are components of the nationwide total and are not added again on top of 21,899.\u003C\u002Fp>\n\u003Cp>Western Alliance said it had no evidence as of the notice date that personal information was misused for fraud or identity theft. That time-bound assessment does not eliminate future risk. Because the actor was confirmed to have obtained file copies and durable identifiers such as SSNs were present, recipients should maintain long-term credit and account monitoring.\u003C\u002Fp>\n\u003Ch2>How Did the Bank Respond and How Can Customers Protect Themselves?\u003C\u002Fh2>\n\u003Cp>Western Alliance notified law enforcement, enhanced technical security measures, and offered eligible people a complimentary one-year Experian IdentityWorks Credit 3B membership. The service includes three-bureau credit monitoring, identity restoration, continued assistance after membership expiration, and identity-theft insurance of up to $1 million subject to terms. Enrollment details are in individual letters.\u003C\u002Fp>\n\u003Cp>Recipients should enroll only with the code in the official letter and review credit reports and Western Alliance accounts for unfamiliar activity. When an SSN or tax ID was involved, freezes at all three credit bureaus, a fraud alert, and an IRS Identity Protection PIN may be appropriate. One-time codes or passwords should not be given in suspicious calls. LeakData does not host incident files or person records.\u003C\u002Fp>","Western Alliance Bank regulatory notice confirming third-party file-transfer exploitation and acquisition of files affecting 21,899 people",false,"Medium","completed","\u002Fuploads\u002Flogo\u002Fwesternalliancebancorporation_com.svg"]