TD Bank Data Breach Lawsuit: Crumpe, Taylor, and New Investigation

A TD Bank data breach lawsuit typically refers to one of the federal class actions filed in 2025 accusing the bank of failing to prevent its own employees from accessing and sharing customer information. One suit was voluntarily dismissed within weeks of filing. Another remains active in New Jersey federal court. A third, newer insider breach reported to the Maine Attorney General is now under investigation by a plaintiffs’ firm evaluating additional claims.

Crumpe v. TD Bank: The Active Class Action

The main pending case is Crumpe v. TD Bank N.A., Case No. 1:25-cv-01566, filed February 28, 2025, in the U.S. District Court for the District of New Jersey. Plaintiff Earl Crumpe alleges that TD Bank failed to implement reasonable data security measures despite known risks, and points to an insider breach that ran from August through December 2022, in which a former employee kept unauthorized access to the bank’s network for roughly five months and acquired names, contact information, dates of birth, account numbers, and transactional data.1Top Class Actions. TD Bank Data Breach Class Action Claims Employee Accessed Customer Data

The complaint brings claims for negligence, breach of implied contract, unjust enrichment, and violations of the Federal Trade Commission Act. It also notes that TD Bank issued two other breach notices in 2024 over similar employee-related incidents, framing the 2022 breach as part of a pattern the bank failed to address. Crumpe seeks declaratory and injunctive relief along with compensatory damages, and has demanded a jury trial.1Top Class Actions. TD Bank Data Breach Class Action Claims Employee Accessed Customer Data

Taylor v. TD Bank: Filed and Dismissed

A separate proposed class action, Taylor v. TD Bank, N.A., Case No. 1:25-cv-00995, was filed on February 4, 2025, in the same New Jersey federal court by Connecticut resident Robert Taylor. Taylor sought at least $5 million in damages on behalf of customers affected by a breach he said occurred between May and October 2023, alleging that TD Bank failed to protect customers from a “massive and preventable” breach and knew about the incident “for some time” before alerting them. The complaint asserted breach of an implied contract, among other claims.2Courier-Post. TD Bank Data Breach Class Action Lawsuit Filed in Camden Federal Court

The case did not last long. Taylor filed a notice of voluntary dismissal on March 23, 2025, and Judge Edward S. Kiel terminated the case the next day.3PACER Monitor. Taylor v. TD Bank, N.A. The file does not state why Taylor withdrew the suit.

A Newer Breach Under Investigation

The most recent known insider incident ran from December 22, 2025, through March 11, 2026, when TD Bank reported that another employee allegedly misused sensitive customer information. The potentially exposed data included names, addresses, phone numbers, dates of birth, Social Security numbers, account numbers, and transactional data. TD Bank reported the incident to the Maine Attorney General.4Federman & Sherwood. TD Bank Data Breach Investigated by Federman and Sherwood

No formal lawsuit has been filed over that incident. As of May 2026, the plaintiffs’ firm Federman & Sherwood is investigating whether TD Bank maintained adequate safeguards to prevent unauthorized internal access to customer data and is evaluating potential legal claims on behalf of affected individuals.4Federman & Sherwood. TD Bank Data Breach Investigated by Federman and Sherwood

The Pattern of Insider Breaches Behind the Suits

The lawsuits share a common thread. TD Bank’s breach problems have not come from outside hackers but from its own employees improperly accessing customer records and, in several cases, handing information to unauthorized third parties. The bank has disclosed a series of these incidents since 2022.

The earliest disclosed incident occurred in May 2022, when a single employee improperly accessed personal information and may have provided it to an outside party, according to a breach notification TD Bank filed with the Vermont Attorney General’s Office. The exposed data included names, addresses, Social Security numbers, dates of birth, account numbers, and transactional information. TD Bank described it at the time as “an isolated incident.”5Vermont Attorney General. TD Bank Data Breach Notice to Consumers

The August-through-December 2022 breach that underlies the Crumpe case followed within months.1Top Class Actions. TD Bank Data Breach Class Action Claims Employee Accessed Customer Data A third incident ran from September 2023 through March 2024, when an employee accessed the data of 41 clients, exposing names, addresses, Social Security numbers, dates of birth, debit card numbers, expiration dates, and security codes. TD Bank notified affected customers in a letter dated August 9, 2024, again calling the incident “an isolated” one.6Cybernews. TD Bank Improperly Accessed Data The 2025–2026 breach makes at least the fourth such disclosure in four years.

What TD Bank Has Offered Affected Customers

In its breach notifications, TD Bank has generally offered affected customers free credit monitoring and identity theft protection. For the 2022 breach, the bank provided a two-year complimentary membership in Fraud-Defender through Merchants Information Solutions, which included continuous monitoring of TransUnion credit files, monitoring of high-risk internet locations including black-market sites, and assignment of a professional identity theft recovery advocate.5Vermont Attorney General. TD Bank Data Breach Notice to Consumers

TD Bank also stated it would cover all expenses for closing and replacing compromised accounts and said it had already reimbursed accounts affected by fraudulent activity. Notification letters directed customers to monitor their credit reports, consider placing fraud alerts or credit freezes with the three major credit bureaus, and report suspicious activity to the FTC and to TD Bank’s fraud unit.5Vermont Attorney General. TD Bank Data Breach Notice to Consumers

What to Do if You Received a Breach Notice

If you got a letter from TD Bank about one of these incidents, keep it. It identifies which breach affected you and often lists the specific data elements exposed, both of which any lawyer or class action administrator will ask for. Activate the credit monitoring the bank offered, and consider a fraud alert or freeze at Equifax, Experian, and TransUnion if your Social Security number was among the exposed data.

Whether you can join a class action depends on which breach affected you. The Crumpe case is tied to the August-to-December 2022 insider incident; a person exposed only in a later breach would not be a class member there. For the 2025–2026 breach, no case has been filed, but Federman & Sherwood is taking information from potentially affected individuals as part of its investigation.4Federman & Sherwood. TD Bank Data Breach Investigated by Federman and Sherwood

Separate TD Bank Matters That Are Not These Lawsuits

Two other TD Bank legal events sometimes appear alongside these cases and are worth distinguishing. The first is a 2012 data breach in which the bank lost two unencrypted backup tapes containing personal information for about 260,000 customers; that matter was resolved through a 2014 multistate settlement of $850,000 and a separate $825,000 Massachusetts settlement, and is a closed regulatory action rather than pending consumer litigation.7New Jersey Office of the Attorney General. Multistate Settlement With TD Bank Over Data Breach8Alston & Bird. Massachusetts v. TD Bank Assurance of Discontinuance

The second is TD Bank’s October 10, 2024, guilty plea to federal money laundering and Bank Secrecy Act charges, which produced penalties exceeding $3 billion and an OCC-imposed cap on the bank’s asset growth.9U.S. Department of Justice. United States of America v. TD Bank, N.A.10ABA Banking Journal. TD Bank Agrees to Pay $3.1 Billion to Resolve AML Allegations That case concerns transaction monitoring, not data security, and its penalties do not go to breach-affected customers. It is often cited by plaintiffs as evidence of a broader compliance culture, but it is not itself a data breach lawsuit and does not give individual customers a claim.