Company Details
bank-of-america-merrill-lynch
17,432
368,409
52
bofaml.com
0
BAN_2040524
In-progress

Bank of America Merrill Lynch Company CyberSecurity Posture
bofaml.comFrom local communities to global markets, we are dedicated to shaping the future responsibly and helping clients thrive in a changing world. “Bank of America Merrill Lynch” is the marketing name for the global banking and global markets businesses of Bank of America Corporation. Bank of America is a marketing name for the Retirement Services business of Bank of America Corporation. Lending, derivatives, and other commercial banking activities are performed globally by banking affiliates of Bank of America Corporation, including Bank of America, N.A., Member FDIC. Securities, strategic advisory, and other investment banking activities are performed globally by investment banking affiliates of Bank of America Corporation (“Investment Banking Affiliates”), including, in the United States, BofA Securities, Inc., Merrill Lynch, Pierce, Fenner & Smith Incorporated, and Merrill Lynch Professional Clearing Corp., all of which are registered broker-dealers and Members of SIPC, and in other jurisdictions, by locally registered entities. BofA Securities, Inc., Merrill Lynch, Pierce, Fenner & Smith Incorporated and Merrill Lynch Professional Clearing Corp. are registered as futures commission merchants with the CFTC and are members of the NFA. Investment products: Are Not FDIC Insured May Lose Value Are Not Bank Guaranteed Any opinions, views, statements, estimates or projections (“posts”) posted on this web page are solely those of the individual author(s). As such, posts by an employee of BofAML or any of its affiliates are solely those of such employee or agent and do not necessarily reflect the views of BofAML. BofAML is not responsible for the content, or output of external websites. For Terms and Conditions and Disclaimers, please visit go.bofaml.com/social. Bank of America LinkedIn Community Guidelines can be found at: http://about.bankofamerica.com/en-us/social-media/linkedin-community-guidelines.html
Company Details
bank-of-america-merrill-lynch
17,432
368,409
52
bofaml.com
0
BAN_2040524
In-progress
Between 750 and 799

BAML Global Score (TPRM)XXXX

Description: The Maine Office of the Attorney General reported a data breach related to Bank of America on March 3, 2025, involving an inadvertent disclosure that occurred on February 18, 2025. One individual was affected, and the compromised information included personal details such as names and Social Security numbers. Bank of America offered a complimentary two-year identity theft protection service by Experian.
Description: On April 16, 2024, the Maine Office of the Attorney General disclosed that Bank of America suffered an **inadvertent data breach** caused by a **Merrill employee’s email error**, leading to the **unauthorized exposure of customer information**. The incident impacted **2,676 individuals**, including **18 Maine residents**, though the exact nature of the exposed data (e.g., financial details, personal identifiers) was not fully specified. In response, Bank of America offered affected individuals **two years of complimentary identity theft protection** via **Experian IdentityWorks™** to mitigate potential risks such as fraud or identity misuse. The breach did not involve malicious cyber activity like hacking or ransomware but stemmed from **human error**, highlighting vulnerabilities in internal data-handling protocols. While no evidence suggested exploitation of the exposed data, the incident underscored the reputational and operational risks associated with **employee-driven data leaks**, particularly for a major financial institution. The breach’s scope—though limited in scale—raised concerns about compliance with data protection regulations and the bank’s ability to safeguard sensitive customer information.
Description: The Maine Office of the Attorney General disclosed a **data breach** affecting **Bank of America**, detected on **October 1, 2024**, and reported on **January 3, 2025**. The incident involved **unauthorized access** to sensitive personal information, compromising **414 individuals**, including at least one Maine resident. While the exact nature of the exposed data was not fully detailed, the breach was severe enough to warrant **24 months of free identity theft protection services via Experian**, suggesting the exposure of personally identifiable information (PII) that could facilitate fraud or identity theft. The breach highlights vulnerabilities in Bank of America’s data security measures, raising concerns over potential financial fraud, reputational damage, and regulatory scrutiny. Although the scale (414 individuals) is relatively contained compared to mass breaches, the provision of long-term identity protection indicates a high-risk exposure—likely involving **financial or identity-related data** (e.g., Social Security numbers, account details, or addresses). The incident underscores the persistent threat of cyber intrusions targeting financial institutions, where even limited breaches can have cascading consequences for affected individuals, including phishing attacks, unauthorized transactions, or credit fraud.
Description: Business clients applying for Paycheck Protection Program (PPP) loans with Bank of America have had their personal and business information exposed in a data breach. The data breach occurred on April 22 as Bank of America uploaded customers’ PPP loan applications to the Small Business Administration’s (SBA) online testing system, which allowed lenders to test application submissions. During the testing process, Application information was potentially visible to other lenders and their third-party vendors. The exposed data included both business and clients’ personal information. The affected business data may include business names, addresses, and tax identification numbers. Affected personal data may include names, addresses, Social Security numbers, phone numbers, email addresses, and citizenship information.


No incidents recorded for Bank of America Merrill Lynch in 2025.
No incidents recorded for Bank of America Merrill Lynch in 2025.
No incidents recorded for Bank of America Merrill Lynch in 2025.
BAML cyber incidents detection timeline including parent company and subsidiaries

From local communities to global markets, we are dedicated to shaping the future responsibly and helping clients thrive in a changing world. “Bank of America Merrill Lynch” is the marketing name for the global banking and global markets businesses of Bank of America Corporation. Bank of America is a marketing name for the Retirement Services business of Bank of America Corporation. Lending, derivatives, and other commercial banking activities are performed globally by banking affiliates of Bank of America Corporation, including Bank of America, N.A., Member FDIC. Securities, strategic advisory, and other investment banking activities are performed globally by investment banking affiliates of Bank of America Corporation (“Investment Banking Affiliates”), including, in the United States, BofA Securities, Inc., Merrill Lynch, Pierce, Fenner & Smith Incorporated, and Merrill Lynch Professional Clearing Corp., all of which are registered broker-dealers and Members of SIPC, and in other jurisdictions, by locally registered entities. BofA Securities, Inc., Merrill Lynch, Pierce, Fenner & Smith Incorporated and Merrill Lynch Professional Clearing Corp. are registered as futures commission merchants with the CFTC and are members of the NFA. Investment products: Are Not FDIC Insured May Lose Value Are Not Bank Guaranteed Any opinions, views, statements, estimates or projections (“posts”) posted on this web page are solely those of the individual author(s). As such, posts by an employee of BofAML or any of its affiliates are solely those of such employee or agent and do not necessarily reflect the views of BofAML. BofAML is not responsible for the content, or output of external websites. For Terms and Conditions and Disclaimers, please visit go.bofaml.com/social. Bank of America LinkedIn Community Guidelines can be found at: http://about.bankofamerica.com/en-us/social-media/linkedin-community-guidelines.html

We help make money work for the world — managing it, moving it and keeping it safe. As a leading global financial services company at the center of the world’s financial system, we touch nearly 20% of the world’s investable assets. Today we help over 90% of Fortune 100 companies and nearly all the t

Old Mutual Limited is a premium pan-African financial services group that offers a broad spectrum of financial solutions to retail and corporate customers across key markets in 14 countries. We have been helping our customers achieve their lifetime financial goals for over 170 years by investing the
Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. Our core activities are safeguarding assets, lending money, making payments and accessing the capital markets on behalf of our clients. We have over 20

Founded in the year 2000, the Indiabulls Group is one of the country’s leading business houses with interest across sectors like financial services, real estate, pharmaceutical and LED. Headquartered in Gurgaon, all the group companies are listed on the Bombay Stock Exchange, and the National Stock

Founded in 1962 and a public company since 1983, Raymond James Financial, Inc. is a Florida-based diversified holding company providing financial services to individuals, corporations and municipalities through its subsidiary companies engaged primarily in investment and financial planning, in addit
Fidelity’s mission is to strengthen the financial well-being of our customers and deliver better outcomes for the clients and businesses we serve. Fidelity’s strength comes from the scale of our diversified, market-leading financial services businesses that serve individuals, families, employers, we

Many know us as the most trusted way to send money to friends and family overseas and across borders, but we're much more than that. Our talented teams around the world are building new ways to send, save and spend money. Wherever you are in the world, in whatever currency you choose, we're evolvi

KPMG is one of the world’s leading professional services firms and the fastest growing Big Four accounting firm in the United States. With 75+ offices and more than 40,000 employees and partners throughout the US, we’re leading the industry in new and exciting ways. Our size and strength make us muc

Franklin Resources, Inc. [NYSE:BEN] is a global investment management organization with subsidiaries operating as Franklin Templeton (www.franklinresources.com). The products, services, information and materials referenced in this site may not be available to residents in certain jurisdictions. Co
.png)
Who: Bank of America warned customers they may have been affected by a November 2023 data breach that occurred as a result of a cybersecurity incident...
Learn how Merrill Edge stacks up against the other brokers we reviewed and how its platform works well for long-term investors who already...
Parthasarathi Chakraborty is a renowned leader with nearly 30 years of experience in cybersecurity defense and engineering.
Launched by Bank of America, Merrill Edge is a secure investment app with backing from one of the largest banks in the United States.
Noteworthy stories that might have slipped under the radar: 2025 trucking cybersecurity report, Bank of America discloses data breach, Silk Typhoon behind US...
State and local governments will never benefit from the same resources as federal agencies — but they can improve security posture with a more...
A new report from Merrill Research delivers a sobering reality check: Only 4% of defense contractors are fully prepared to meet the Department of Defense...
The Financial Industry Regulatory Authority issued two separate fines against Merrill Lynch and BofA Securities totaling nearly $2.3 million...
If you're looking for the safest and most secure trading apps of this moment, you're in the right place! Check out our full guide for a top...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Bank of America Merrill Lynch is http://www.bofaml.com.
According to Rankiteo, Bank of America Merrill Lynch’s AI-generated cybersecurity score is 787, reflecting their Fair security posture.
According to Rankiteo, Bank of America Merrill Lynch currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Bank of America Merrill Lynch is not certified under SOC 2 Type 1.
According to Rankiteo, Bank of America Merrill Lynch does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Bank of America Merrill Lynch is not listed as GDPR compliant.
According to Rankiteo, Bank of America Merrill Lynch does not currently maintain PCI DSS compliance.
According to Rankiteo, Bank of America Merrill Lynch is not compliant with HIPAA regulations.
According to Rankiteo,Bank of America Merrill Lynch is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Bank of America Merrill Lynch operates primarily in the Financial Services industry.
Bank of America Merrill Lynch employs approximately 17,432 people worldwide.
Bank of America Merrill Lynch presently has no subsidiaries across any sectors.
Bank of America Merrill Lynch’s official LinkedIn profile has approximately 368,409 followers.
Bank of America Merrill Lynch is classified under the NAICS code 52, which corresponds to Finance and Insurance.
No, Bank of America Merrill Lynch does not have a profile on Crunchbase.
Yes, Bank of America Merrill Lynch maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/bank-of-america-merrill-lynch.
As of December 11, 2025, Rankiteo reports that Bank of America Merrill Lynch has experienced 4 cybersecurity incidents.
Bank of America Merrill Lynch has an estimated 30,346 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Data Leak and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with experian, and remediation measures with complimentary two-year identity theft protection service, and incident response plan activated with likely (standard protocol for data breaches), and third party assistance with experian (identityworks™ services), and remediation measures with offering 2-year complimentary identity theft protection (experian identityworks™), and communication strategy with notification to affected individuals via maine ag report, and third party assistance with experian (identity theft protection)..
Title: Bank of America PPP Loan Data Breach
Description: Business clients applying for Paycheck Protection Program (PPP) loans with Bank of America have had their personal and business information exposed in a data breach.
Date Detected: April 22, 2020
Type: Data Breach
Attack Vector: Improper Data Handling
Vulnerability Exploited: Improper Data Handling
Title: Bank of America Data Breach
Description: The Maine Office of the Attorney General reported a data breach related to Bank of America on March 3, 2025, involving an inadvertent disclosure that occurred on February 18, 2025. One individual was affected, and the compromised information included personal details such as names and Social Security numbers. Bank of America offered a complimentary two-year identity theft protection service by Experian.
Date Detected: 2025-02-18
Date Publicly Disclosed: 2025-03-03
Type: Data Breach
Attack Vector: Inadvertent Disclosure
Title: Bank of America Inadvertent Disclosure of Customer Information via Merrill Employee Email Error
Description: The Maine Office of the Attorney General reported that Bank of America experienced an inadvertent disclosure of customer information on April 16, 2024, due to a Merrill employee email error, affecting a total of 2,676 individuals, including 18 Maine residents. Bank of America is offering a complimentary two-year membership in identity theft protection services through Experian IdentityWorks™.
Date Detected: 2024-04-16
Date Publicly Disclosed: 2024-04-16
Type: Data Breach (Inadvertent Disclosure)
Attack Vector: Human Error (Email Misconfiguration)
Title: Bank of America Data Breach (2024)
Description: The Maine Office of the Attorney General reported a data breach involving Bank of America. The breach occurred on October 1, 2024, affecting 414 individuals, including 1 resident of Maine. Unauthorized access was detected, and identity theft protection services (24 months via Experian) were offered to affected individuals.
Date Detected: 2024-10-01
Date Publicly Disclosed: 2025-01-03
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Business names, Addresses, Tax identification numbers, Names, Social security numbers, Phone numbers, Email addresses, Citizenship information

Data Compromised: Names, Social security numbers
Identity Theft Risk: High

Data Compromised: Customer information
Brand Reputation Impact: Potential (Mitigated by Identity Theft Protection Offer)
Identity Theft Risk: High (Mitigated by Experian IdentityWorks™ Offer)

Identity Theft Risk: True
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Business Names, Addresses, Tax Identification Numbers, Names, Social Security Numbers, Phone Numbers, Email Addresses, Citizenship Information, , Personal Information, and Customer Information (Details Unspecified).

Entity Name: Bank of America
Entity Type: Financial Institution
Industry: Banking

Entity Name: Bank of America
Entity Type: Financial Institution
Industry: Banking
Customers Affected: 1

Entity Name: Bank of America (via Merrill)
Entity Type: Financial Institution
Industry: Banking/Financial Services
Location: United States (Maine residents among affected)
Size: Large (Multinational)
Customers Affected: 2,676 (including 18 Maine residents)

Entity Name: Bank of America
Entity Type: Financial Institution
Industry: Banking/Financial Services
Location: United States
Customers Affected: 414

Third Party Assistance: Experian.
Remediation Measures: Complimentary two-year identity theft protection service

Incident Response Plan Activated: Likely (Standard Protocol for Data Breaches)
Third Party Assistance: Experian (Identityworks™ Services).
Remediation Measures: Offering 2-year complimentary identity theft protection (Experian IdentityWorks™)
Communication Strategy: Notification to affected individuals via Maine AG report

Third Party Assistance: Experian (Identity Theft Protection).
Incident Response Plan: The company's incident response plan is described as Likely (Standard Protocol for Data Breaches).
Third-Party Assistance: The company involves third-party assistance in incident response through Experian, , Experian (IdentityWorks™ Services), , Experian (Identity Theft Protection), .

Type of Data Compromised: Business names, Addresses, Tax identification numbers, Names, Social security numbers, Phone numbers, Email addresses, Citizenship information
Sensitivity of Data: High

Type of Data Compromised: Personal information
Number of Records Exposed: 1
Sensitivity of Data: High
Personally Identifiable Information: NamesSocial Security numbers

Type of Data Compromised: Customer Information (Details Unspecified)
Number of Records Exposed: 2,676
Sensitivity of Data: Moderate to High (PII likely included)
Personally Identifiable Information: Likely (Given Identity Theft Protection Offer)

Number of Records Exposed: 414
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Complimentary two-year identity theft protection service, , Offering 2-year complimentary identity theft protection (Experian IdentityWorks™), .

Regulatory Notifications: Maine Office of the Attorney General

Regulatory Notifications: Maine Office of the Attorney General

Source: Maine Office of the Attorney General
Date Accessed: 2025-03-03

Source: Maine Office of the Attorney General
Date Accessed: 2024-04-16

Source: Maine Office of the Attorney General
Date Accessed: 2025-01-03
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2025-03-03, and Source: Maine Office of the Attorney GeneralDate Accessed: 2024-04-16, and Source: Maine Office of the Attorney GeneralDate Accessed: 2025-01-03.

Investigation Status: Disclosed (No Further Details)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notification To Affected Individuals Via Maine Ag Report.

Customer Advisories: Offer of 2-year Experian IdentityWorks™ membership

Customer Advisories: Identity theft protection services (24 months via Experian) offered to affected individuals
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Offer Of 2-Year Experian Identityworks™ Membership, , Identity Theft Protection Services (24 Months Via Experian) Offered To Affected Individuals and .

Root Causes: Human Error (Merrill Employee Email Misconfiguration),
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Experian, , Experian (Identityworks™ Services), , Experian (Identity Theft Protection), .
Most Recent Incident Detected: The most recent incident detected was on April 22, 2020.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-01-03.
Most Significant Data Compromised: The most significant data compromised in an incident were Business names, Addresses, Tax identification numbers, Names, Social Security numbers, Phone numbers, Email addresses, Citizenship information, , Names, Social Security numbers, , Customer Information, and .
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was experian, , experian (identityworks™ services), , experian (identity theft protection), .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Phone numbers, Names, Email addresses, Business names, Social Security numbers, Tax identification numbers, Addresses, Citizenship information and Customer Information.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 3.1K.
Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Disclosed (No Further Details).
Most Recent Customer Advisory: The most recent customer advisory issued were an Offer of 2-year Experian IdentityWorks™ membership and Identity theft protection services (24 months via Experian) offered to affected individuals.
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.