Menu
Banking Exchange Magazine Logo
Menu

Jack Henry Cyberattack Compromises Client Data

US banking technology provider says core platforms and daily processing services remained operational

  • |
  • Written by  Banking Exchange staff
 
 
Jack Henry Cyberattack Compromises Client Data

US banking technology provider Jack Henry has disclosed a cybersecurity incident that compromised personally identifiable information.

The company did not disclose how many individual account holders were affected, what information was exposed or when the attack occurred.

The attack was confined to a limited part of the company’s internal, non-production corporate environment. Jack Henry said no client-facing systems, core banking platforms or daily processing services were accessed or disrupted, and there were no system outages.

The company attributed the incident to a voice-phishing attack by the threat actor ShinyHunters. Voice phishing, also known as vishing, uses telephone calls to persuade employees to reveal sensitive information or provide access to systems.

Jack Henry’s security controls detected and contained the unauthorized activity. The company isolated the affected systems and appointed an independent cyber-forensics firm to support its investigation.

It is also working with federal law enforcement. Jack Henry notified all of its more than 7,200 clients that an incident had occurred, although it said the compromised information related to fewer than 10 clients.

The company is working directly with the affected institutions and offering two years of credit monitoring for them to make available to impacted account holders.

The attackers attempted to extort the company, but Jack Henry said it would not make a payment. It has determined that the incident is not financially material.

Although its banking platforms remained operational, the incident highlights the risks banks and credit unions can face through technology suppliers that hold customer information.

US banking regulators expect institutions to manage risks throughout their relationships with third-party providers, with oversight reflecting the importance of the services and information involved.

back to top

Sections

About Us

Connect With Us

Resources