JPMorgan Chase, the largest US bank by assets, disclosed in a regulatory filing that a cyber attack had compromised contact information for about 76 million households and 7 million small businesses.
What happened
- Exposed data included names, addresses, phone numbers, and email addresses, along with internal bank information about customers.
- The bank said there was no evidence that account numbers, passwords, user IDs, dates of birth, or Social Security numbers were compromised.
- The bank said it had seen no unusual customer fraud linked to the incident.
- Other financial institutions were reported to have been targeted in the same campaign.
Why it mattered
The breach was one of the largest ever at a bank and increased scrutiny of cyber security in the financial sector. Later US prosecutions linked it to a wider securities fraud scheme.
Lessons for organisations
Even contact data is valuable to criminals for phishing and fraud, so it deserves protection. Organisations should apply multi-factor authentication across all servers, including less prominent ones, and warn customers to be alert to targeted scams after a breach.
Sources: CNBC, BankInfoSecurity
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.