Editorial draft v1 · Evidence reader R1 · Evidence cutoff: May 14, 2024

Disclosures covered: Santander's May 14, 2024 statement in its Form 6-K. This is a bounded initial-disclosure account, with no later outcome established by the selected source.

Santander disclosed unauthorized access to a database hosted by a third-party provider on May 14, 2024. Its investigation confirmed access to certain customer and employee information, while the bank said its operations and systems were unaffected. The statement distinguishes an information-access incident from disruption to banking transactions, but leaves the database provider, precise timing, and size of the affected population unspecified. Santander statement

The information and people Santander identified

Santander said the accessed information related to customers in Chile, Spain, and Uruguay, as well as all current and some former employees across the group. It said customer data in other markets and businesses was unaffected. This describes the scope Santander reported; it does not establish that every customer in the three countries was affected, or that all information relating to those customers was accessed. No numerical population was supplied. Santander statement

According to the bank, the database contained neither transactional data nor credentials that would enable account transactions, including online-banking details and passwords. Santander said customers could continue to transact securely because bank operations and systems were not affected. Those statements concern the database's contents and the operational position at the time. They do not negate the confirmed access to other information or independently establish the absence of every fraud risk. Santander statement

Containment and notification

The bank said it had blocked the compromised access and added fraud-prevention controls to protect affected customers. It was contacting affected customers and employees directly and had notified regulators and law enforcement. The source describes these measures at a high level; it does not explain the intrusion technique or provide a completed forensic account. Santander statement

Editorial interpretation: the disclosure is useful for its explicit boundaries—named customer markets, a separate group-wide employee scope, and a distinction between accessed information and transaction-enabling credentials. Its brevity also matters. It does not support a named hosting provider, attacker, ransom payment, financial-loss figure, total affected-person count, or later recovery outcome. This article therefore ends with the May 14 account rather than presenting an initial statement as a complete incident history. Santander statement

Sources

Disclosure history

Article draft version 1 · Evidence reader revision 1 · Evidence cutoff May 14, 2024, 12:00 AM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • U.S. Securities and Exchange Commission Filed May 14, 2024Statement/document date: May 14, 2024Document form: 6-K · Item Document's Item1, Report of Other Relevant Information; not domestic8-K Item1.05SEC HTTPS source · Retrieved Oct 7, 2026, 2:31 PM UTC · Retained Oct 7, 2026, 2:31 PM UTC