Monday, August 3, 2026

Policy & Regulation

Community Bank reports security lapse involving AI chatbot

Community Bank disclosed a cybersecurity incident where customer data was potentially exposed after an employee used an unauthorized AI application.

Community Bank reports security lapse involving AI chatbot

Community Bank, a US regional bank operating in Pennsylvania, Ohio, and West Virginia, has disclosed a cybersecurity incident that exposed customer information. The security lapse affected customer data, including names, dates of birth, and Social Security numbers of customers within these states. According to Community Bank, a regional bank, the exposure was due to the use of “an unauthorized artificial intelligence-based software application.” While the exact details of the exposure remain unclear, it appears someone working for the bank may have uploaded customer data to an online AI chatbot, potentially exposing that information to the chatbot developer.

The bank detailed the cybersecurity incident in an 8-K filing dated May 7, which was submitted to the U.S. Securities and Exchange Commission, the US financial regulator. An 8-K filing is a form used by public companies in the US to announce major events that shareholders should know about. In this regulatory filing, the bank stated that it chose to disclose the incident because of the volume and sensitive nature of the private information involved. Despite the filing, Community Bank did not disclose the exact number of customers whose information was affected, nor did it name the specific artificial intelligence application that was utilized by the employee. The filing serves as the primary public record of the incident, outlining the bank’s initial response and its ongoing efforts to address the security lapse.

Currently, the bank is assessing the customer data that was affected by the unauthorized software use. The company also stated that it is sending out notifications to the affected individuals in accordance with relevant laws to inform them of the exposure. The security lapse was first reported by the publication The Register on May 12. John Montgomery, the chief executive of Community Bank, did not immediately respond to TechCrunch’s request for comment.

Why it matters

This incident highlights the growing enterprise risk of shadow AI, where employees use unauthorized tools that may inadvertently ingest sensitive customer data, forcing banks to navigate complex disclosure requirements.