Close Menu
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
What's Hot

Stockpile review 2024

June 12, 2025

Bangladesh considers ‘settlements’ with tycons accused of funnelen abroad abroad

June 12, 2025

‘Oh crikey!’ Westpac tips 2026 to bring more RBA cuts

June 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Smart SpendingSmart Spending
Subscribe
  • Home
  • Finance News
  • Personal Finance
  • Investing
  • Cards
    • Credit Cards
    • Debit
  • Insurance
  • Loans
  • Mortgage
  • More
    • Save Money
    • Banking
    • Taxes
    • Crime
Smart SpendingSmart Spending
Home»Banking»Bank groups warn of regulators’ cybersecurity weaknesses
Banking

Bank groups warn of regulators’ cybersecurity weaknesses

June 10, 2025No Comments4 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Bank groups warn of regulators’ cybersecurity weaknesses
Share
Facebook Twitter LinkedIn Pinterest Email

Major financial trade associations sent a joint letter Monday to U.S. Treasury Secretary Scott Bessent calling for reforms to address what they called “preparedness gaps” and “security weaknesses” at federal financial regulatory agencies.

The letter came from the American Bankers Association, Bank Policy Institute, Managed Funds Association and Securities Industry and Financial Markets Association. The groups expressed concern that regulators’ own security weaknesses introduce unnecessary risk to the firms they regulate.

The trade associations highlighted recent cybersecurity incidents at the Office of the Comptroller of the Currency and the Department of the Treasury in December 2024, saying in the letter these incidents show that “government agencies are increasingly the target of persistent and sophisticated nation state attacks that could disrupt financial markets and our economy.”

The associations asserted that it is “imperative that federal regulators recognize that they are equally a target of malicious actors and implement the same or substantially similar cybersecurity and incident response practices that they expect financial institutions to maintain.”

The letter notes that inadequate security at regulatory agencies has been a long-standing issue. Firms are legally required to share sensitive, proprietary and nonpublic information with regulators as part of the supervisory process. The groups contend that centralizing large amounts of this data can create a prime target for malicious actors. Compromises at regulatory agencies could expose institutions’ vulnerabilities and business information.

Details of the OCC email breach

The letter specifically referenced the OCC’s email system breach, which exposed an estimated 148,000 emails.

Hackers compromised the OCC’s systems in May 2023, and the OCC learned of the suspicious activity in February 2025, meaning hackers likely had access for over a year and a half.

See also  NY State passes BNPL oversight in 2026 budget | PaymentsSource

Microsoft Global Hunting Oversight and Strategic Triage, or GHOST, notified the OCC on February 11 about unusual interactions, and the OCC confirmed the activity was unauthorized on February 12.

The OCC initially communicated in its first public notice in February 2025 that there was “no indication of any impact to the financial sector.” However, during subsequent reviews, the OCC learned the incident impacted sensitive information. On April 7, 2025, the OCC determined the incident qualified as a major incident under the Federal Information Security Modernization Act, or FISMA.

The OCC notified Congress on April 8, stating the compromise included unauthorized access to “highly sensitive information relating to the financial condition of federally regulated financial institutions.”

Information accessed included financial supervision information provided by supervised institutions and nonpublic OCC information. Efforts to determine if any bank customer information was compromised were ongoing as of an April update on the matter from the OCC.

Once informed of the incident, financial institutions activated their third-party risk management procedures, including disconnecting from the OCC and pausing the transfer of sensitive information.

Recommendations for reform

To mitigate risk and prevent similar problems, the trade groups made four recommendations to Bessent in the Monday letter:

  • Ensure agencies are held to the same or substantively similar security and data protection standards expected of financial institutions, including transparency and accountability. They recommended experienced examiners who review regulated entities also review internal agency systems.
  • Enable firms to retain and house their own sensitive data needed for regulatory engagement on their own secure systems. Regulators should stop requiring firms to submit sensitive data through online portals or email and instead access data via on-site review or on firm computers with security controls.
  • Improve regulatory agencies’ incident response processes to include notification and communication with regulated institutions. They urged agencies to notify affected entities within 72 hours, consistent with recommendations from a 2022 Data Protection Working Group report and upcoming requirements under the Cyber Incident Reporting for Critical Infrastructure Act. They noted the OCC’s response did not come close to meeting the 36-hour notification requirement imposed on financial institutions.
  • Consolidate and streamline examinations conducted by financial regulatory agencies to reduce the amount of data being shared. They suggested requests for data be subject to consistent review by senior supervisory officials to minimize unnecessary data collection.
See also  Regulators should stop trying to 'whack' so-called junk fees

The letter concludes by stating the financial services industry is ready to partner with the administration and regulators to ensure financial markets are guarded against adversaries and protect the vitality of the U.S. economy.

Source link

Bank Cybersecurity groups regulators warn weaknesses
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
Previous Article12 Reasons You Will Never Be A Multi-Millionaire
Next Article Supreme Court gives DOGE access to personal Social Security data

Related Posts

Ex-First Republic execs win dismissal of shareholder suit

June 12, 2025

Is third time the charm for Basel III endgame?

June 12, 2025

Senate stablecoin bill passes a key procedural vote

June 11, 2025
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Can You Get Business Credit Cards With No Personal Credit Checks?

October 10, 2024

Jamie Dimon on Trump’s tariffs: ‘Get over it’

January 23, 2025

Universal Epic Universe: How to Plan Your Trip for the Opening

February 6, 2025
Ads Banner

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

Stay informed with our finance blog! Get expert insights, money management tips, investment strategies, and the latest financial news to help you make smart financial decisions.

We're social. Connect with us:

Facebook X (Twitter) Instagram YouTube
Top Insights

Stockpile review 2024

June 12, 2025

Bangladesh considers ‘settlements’ with tycons accused of funnelen abroad abroad

June 12, 2025

‘Oh crikey!’ Westpac tips 2026 to bring more RBA cuts

June 12, 2025
Get Informed

Subscribe to Updates

Subscribe to Get the Latest Financial Tips and Insights Delivered to Your Inbox!

© 2025 Smartspending.ai - All rights reserved.
  • Contact
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.