Comparison Overview
Bank of America Merrill Lynch

Bank of America Merrill Lynch
100 North Tryon Street, Charlotte, 28255, US
Last Update: 01/04/2026
From local communities to global markets, we are dedicated to shaping the future responsibly and helping clients thrive in a changing world. “Bank of America Merrill Lynch” is the marketing name for the global banking and global markets businesses of Bank of America Co...

Chase
270 Park Avenue, New York, 10172, US
Last Update: 05/04/2026
At Chase, we’re dedicated to helping you succeed. Whether you’re in need of banking, credit cards, mortgages, auto financing, investment guidance, small business support, or payment solutions, we’re beside you every step of the way. For customer service, contact us via...
Compliance Ranges Comparison

Bank of America Merrill Lynch







Chase






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for Bank of America Merrill Lynch in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for Chase in 2026.
Incident History - Bank of America Merrill Lynch (X = Date, Y = Severity)
Bank of America Merrill Lynch cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Chase (X = Date, Y = Severity)
Chase cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Bank of America Merrill Lynch

Chase
FAQ
Latest Global CVEs
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.